We have an application that is integrated with splunk. We have a C++ program that was written as a plugin (bundle or application now I guess) and it is linked against the "extcmdapi" library. This plugin is used to introduce meta tags from our product into the raw data as its being indexed. We originally wrote this against 2.x of splunk and seems to work OK against 3.x.
I'm trying to find more info if this approach is still supported under 4.x. It sounds like one approach is to do the processing up front and feed replaced raw data to splunk on stdout, but looking for confirmation. Can't find much info on our current method on the site.