Dashboards & Visualizations

Splunk App Add On

arabhi
New Member

I try to add custom visualisation on my splunk enterprise, but I am not able to find add file option in manage app. Is there any role needed to get such option on my splunk?

Labels (4)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @arabhi,
are you speaking of add file for data ingestion or add file to App (e.g. icons or images or css or js)?

if you are speaking of data inputs, you can create your data inputs on the same machine or in a different one, following the instructions in https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Getstartedwithgettingdatain or https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Usingforwardingagents .

If instead you want to add a file to your app, you can manually put them in $SPLUNK_HOME/etc/apps/your_app/appserver/static (but you have to restart Splunk) otherwise, you can do this by GUI at [Apps -- Manage apps -- your_app -- Edit Properties -- Upload asset] without Splunk restarting.

Ciao.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @arabhi,
are you speaking of add file for data ingestion or add file to App (e.g. icons or images or css or js)?

if you are speaking of data inputs, you can create your data inputs on the same machine or in a different one, following the instructions in https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Getstartedwithgettingdatain or https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Usingforwardingagents .

If instead you want to add a file to your app, you can manually put them in $SPLUNK_HOME/etc/apps/your_app/appserver/static (but you have to restart Splunk) otherwise, you can do this by GUI at [Apps -- Manage apps -- your_app -- Edit Properties -- Upload asset] without Splunk restarting.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...