All Apps and Add-ons

Splunk App structure: SAs and TAs

user21041983
Explorer

Hi All,

Am a newbie to Splunk and wanting to know the best practices for creating a scalable Splunk app.

Are there any sample tutorials where we can understand how the SA (Supporting Add-ons) and TAs (Technology Add-ons) should be created?

Also, how are they bounded together in the master app?

0 Karma

MuS
Legend

Hi user21041983,

Check out the docs docs.splunk.com/Documentation/Splunk/6.2.0/Admin/Whatsanapp

Cheers, MuS

user21041983
Explorer

Thanks MuS. Having understood the basics of TAs/SAs/Apps, I wanted to know the secret sauce i.e. How the TAs and SAs come together and function together at runtime based on whether they are installed or not in /etc/apps. Maybe amateur to ask, but which configs/settings define that behaviour?

0 Karma

MuS
Legend

Ah, okay, an app or SA or TA are basically the same thing. It's like in the docs writen a collection of settings. All work the same way and this is explained in the docs as well http://docs.splunk.com/Documentation/Splunk/6.2.0/Admin/Wheretofindtheconfigurationfiles

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...