Splunk Dev

[New App] TA Studio — a browser-based GUI for building Splunk add-ons (feedback & testers wanted)

jbspecht
Explorer

Hi all,

TA Studio wraps the official UCC Framework, giving you a modern, browser-based way to build Splunk add-ons. You can create data inputs, setup pages, sourcetypes, field extractions, CIM mappings, alert actions, and more — all through a point-and-click UI — then build a Splunkbase ready package at the click of a button. 

Other features include CSV and KV Store lookups, event types & tags, field transforms, workflow actions, saved searches, dashboard packaging, a live input/alert test runner, raw globalConfig.json and .conf editors for full control, AppInspect validation with run history, and optional AI assistance (bring your own API key).

The goal was to have an alternative to Splunk's Add-on Builder that does more, runs faster, and clears the compatibility hurdles for development — cross-platform on Windows and Linux.

Requirements: Splunk Enterprise 9.2.0+ (tested through 10.4.0), with splunk-add-on-ucc-framework and splunk-appinspect installed into Splunk's bundled Python. Full install steps are on the Splunkbase listing.

I'd love your help testing it 🙏

This is a solo project, so real-world feedback is gold. If you give it a try and spot a bug or think of a useful enhancement, please email me at [email protected] with the details (steps to reproduce, your Splunk/OS version, and any logs help a lot).

As a small thank-you: if you report a valid bug or a beneficial enhancement, I'll happily add your name or username to a Testers section on TA Studio's About page.

Thanks for reading — and thanks in advance to anyone who kicks the tires.

Labels (5)
0 Karma

jbspecht
Explorer

Version 1.5.0 was released on 7/4/2026. It includes some major updates and bug fixes.

 

  • Dashboards page — bundle exported Simple XML / Dashboard Studio views; auto-added to add-on nav
  • Saved Searches & Reports page — manage savedsearches.conf with scheduling
  • Workflow Actions page — link and search drilldowns from result fields
  • Field Transforms page — delimited, multivalue, and reusable regex extractions
  • KV Store lookups — in addition to CSV lookups
  • Automatic lookups — apply a lookup to a source type at search time (LOOKUP-)
  • Field aliases (FIELDALIAS-) and calculated fields (EVAL-)
  • Search Macros page — manage parameterized macros.conf
  • Object tagging — full tags.conf manager (event types, hosts, sources, source types)
  • Raw .conf file editor — edit any conf under package/default/ verbatim, with AI assist
  • CIM compliance checker — scores a source type against every CIM data model
  • AI-generated app icons — flat SVG icons from a text description
  • xAI (Grok) added as an AI provider
  • AI input code is auto-tested and self-corrected (up to 2 fix attempts)
  • Cloud validation now runs SLIM packaging check

This version supports adding/editing pretty much any type of knowledge object that's provided in Splunk and then provides access to the raw confs/code files/globalConfig for editing anything else.

Next version is due out in a couple weeks and will have a focus on simplifying the add-on open process so that no matter how the add-on was created (manual, add-on builder, UCC, export) they all open through the same Open button/drag-n-drop. 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...