Splunk® Style Guide

Splunk Style Guide

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Splunk product terminology

Splunk docs use standard terms and definitions for Splunk software, certain combinations of Splunk software, and parts of Splunk product architecture. Follow these usage guidelines to choose the correct term when you write about Splunk software.

Splunk by itself

When used alone, "Splunk" refers only to the company, not to any product. Don't use "Splunk" in the possessive form.

Splunk software

Use Splunk software to refer to anything and everything the company offers. Don't capitalize the "s" in "software", and don't include a definite article.

Correct
Splunk software
Incorrect
The Splunk software
The Splunk Software
the Splunk Software
Splunk Software

The Splunk platform

Use the Splunk platform to refer to both Splunk Cloud Platform and Splunk Enterprise. Don't capitalize the "p" in "platform", and make sure you include a definite article.

Correct
The Splunk platform
the Splunk platform
Incorrect
The Splunk Platform
Splunk platform

You can use "the Splunk platform" or "Splunk platform" without a definite article as a modifier. Avoid using "Splunk" as a modifier by itself when you are referring to a specific instance where the Splunk platform is installed, Splunk platform deployments, or the environment in which the Splunk platform is running.

Correct
Restart the Splunk platform instance...
In a distributed Splunk platform deployment...
In your Splunk platform environment...
Incorrect
Splunk platform server
Splunk server
Splunk deployment
Splunk instance
Splunk environment
Splunk implementation

Splunk platform architecture components

Don't capitalize Splunk platform architecture components such as indexers, forwarders, search heads, license managers, and deployment servers. If you are unsure how to capitalize a Splunk term, see the Splexicon for the correct capitalization.

Choose the most specific and accurate term in each situation

When considering what noun to use when referring to a Splunk product, always use the most specific and accurate term that is appropriate for the situation. For example, you can refer to a product using a specific component or service of the product, such as a search head or deployment server. If you need a more general term, refer to the product by its product name, such as Splunk Enterprise or Splunk Cloud Platform, or its product category, such as the Splunk platform. If you must refer to both a Splunk platform product and an app, you can use the most general term, "Splunk software".

Use these guidelines to determine which term to write:

  • If you're thinking about using Splunk Enterprise or Splunk Cloud Platform, consider whether a specific component of the product, like the search head, the indexer cluster, Splunk Web, the data collection node, the deployment server, the forwarder, and so on, is more helpful for customers.
  • When you are referring to a specific Splunk platform product, name it.
  • When you are referring to an app, name the app or write "the app". Don't use "premium apps" or "premium solutions".
  • When you are referring to Splunk Cloud Platform or Splunk Enterprise but you don't know which product the user has, write "the Splunk platform". This is common.
  • Use "Splunk software" only when you are referring to one or more Splunk platform products plus one or more apps, or when either a Splunk platform product or an app can be the subject. This is the rarest case.

Here are examples of Splunk product terms in a sentence with an explanation of why the term in bold is the best term to use:

Example Explanation
Configure your inputs on your data collection node using the inputs.conf file or Splunk Web. The most specific and accurate term here is the component on which the configuration takes place.
The performance of this application is dependent on a variety of factors, including the other Splunk apps that you have installed on the same search head. Because this sentence is about search head performance, "search head" is the most specific and accurate term in this situation. Also, "Splunk apps" is the most specific and accurate term rather than "Splunk software" because apps, not the Splunk platform, are what users can install on a search head.
This manual discusses high-level hardware guidance for Splunk Enterprise deployments and describes how Splunk Enterprise uses hardware resources in different situations. The Capacity Planning Manual applies only to Splunk Enterprise, so you can be specific and name the product.
The Splunk Datasets Add-on, available from Splunkbase, gives Splunk Enterprise users additional dataset management capabilities. Splunk Cloud Platform users have the Splunk Datasets Add-on by default. ... In previous versions of the Splunk platform, data model datasets were called data model objects. The initial entry point for this feature is different in Splunk Enterprise and Splunk Cloud Platform, so be clear up front by using the product names. For the remainder of the documentation, "the Splunk platform" is appropriate because it includes both Splunk Enterprise and Splunk Cloud Platform.
Metrics is a feature of the Splunk platform. The metrics feature is available for Splunk Cloud Platform and Splunk Enterprise, so the Metrics manual uses "the Splunk platform" to be inclusive of all platform types.
Splunk IT Service Intelligence uses the access control system integrated with the Splunk platform. You don't know whether the customer is administering ITSI on Splunk Enterprise or Splunk Cloud Platform, so use "the Splunk platform" here to be inclusive of both.
Splunk Education offers a variety of courses and certification programs to help make you more productive with Splunk software. Splunk Education courses cover apps as well as Splunk platform products, so using "Splunk software" is appropriate here.
If you have questions about the licenses that apply to the Splunk software you are using, contact Splunk Support. Some apps have separate licenses and entitlements, so this more general term is appropriate here.

Still not sure which term to use?

Try these steps:

  1. First, try to name the specific component or product. If that level of precision is appropriate, use that term.
  2. If the specific component or product name isn't appropriate, try using "the Splunk platform". When you use "the Splunk platform" in the sentence, can you replace it with at least one of the following things and have the sentence still make sense?
    • "Splunk Enterprise or Splunk Cloud Platform"
    • "your forwarder or your single-instance deployment"
    If yes, use "the Splunk platform".
  3. If "the Splunk platform" doesn't make sense, try using "Splunk software". When you use "Splunk software" in the sentence, can you replace it with at least one of the following things and have the sentence still make sense?
    • "the Splunk platform or a Splunk app"
    • "the Splunk platform or Splunk apps"
    • "the Splunk platform or some Splunk apps"
    • "Splunk Enterprise or Splunk apps"
    • "Splunk Enterprise or some Splunk apps"
    • "Splunk Cloud Platform or cloud-supported Splunk apps"
    If yes, use "Splunk software". If no, ask the editing team for advice.

Splunk Observability Cloud

Splunk offers Splunk Observability Cloud as a cloud-only product suite that is separate from the Splunk platform product offerings.

When referring to this offering, follow these conventions:

  • Don't omit "Splunk" to shorten the name.
  • Don't use an acronym, such as SOC, to refer to this offering.
  • Don't use the definite article "the" in front of the product name.
  • Don't refer to this offering as a "platform".
Correct
Splunk Observability Cloud
Incorrect
Observability Cloud
SOC
The Splunk Observability Cloud
Splunk Observability Cloud platform
Last modified on 17 July, 2023
PREVIOUS
Slashes
  NEXT
Splunk Web terminology

This documentation applies to the following versions of Splunk® Style Guide: current


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters