All Apps and Add-ons

Splunk App structure: SAs and TAs

user21041983
Explorer

Hi All,

Am a newbie to Splunk and wanting to know the best practices for creating a scalable Splunk app.

Are there any sample tutorials where we can understand how the SA (Supporting Add-ons) and TAs (Technology Add-ons) should be created?

Also, how are they bounded together in the master app?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi user21041983,

Check out the docs docs.splunk.com/Documentation/Splunk/6.2.0/Admin/Whatsanapp

Cheers, MuS

user21041983
Explorer

Thanks MuS. Having understood the basics of TAs/SAs/Apps, I wanted to know the secret sauce i.e. How the TAs and SAs come together and function together at runtime based on whether they are installed or not in /etc/apps. Maybe amateur to ask, but which configs/settings define that behaviour?

0 Karma

MuS
SplunkTrust
SplunkTrust

Ah, okay, an app or SA or TA are basically the same thing. It's like in the docs writen a collection of settings. All work the same way and this is explained in the docs as well http://docs.splunk.com/Documentation/Splunk/6.2.0/Admin/Wheretofindtheconfigurationfiles

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...