Am a newbie to Splunk and wanting to know the best practices for creating a scalable Splunk app.
Are there any sample tutorials where we can understand how the SA (Supporting Add-ons) and TAs (Technology Add-ons) should be created?
Also, how are they bounded together in the master app?
Thanks MuS. Having understood the basics of TAs/SAs/Apps, I wanted to know the secret sauce i.e. How the TAs and SAs come together and function together at runtime based on whether they are installed or not in /etc/apps. Maybe amateur to ask, but which configs/settings define that behaviour?
Ah, okay, an app or SA or TA are basically the same thing. It's like in the docs writen a collection of settings. All work the same way and this is explained in the docs as well http://docs.splunk.com/Documentation/Splunk/6.2.0/Admin/Wheretofindtheconfigurationfiles