Hi all,
TA Studio wraps the official UCC Framework, giving you a modern, browser-based way to build Splunk add-ons. You can create data inputs, setup pages, sourcetypes, field extractions, CIM mappings, alert actions, and more — all through a point-and-click UI — then build a Splunkbase ready package at the click of a button.
Other features include CSV and KV Store lookups, event types & tags, field transforms, workflow actions, saved searches, dashboard packaging, a live input/alert test runner, raw globalConfig.json and .conf editors for full control, AppInspect validation with run history, and optional AI assistance (bring your own API key).
The goal was to have an alternative to Splunk's Add-on Builder that does more, runs faster, and clears the compatibility hurdles for development — cross-platform on Windows and Linux.
Requirements: Splunk Enterprise 9.2.0+ (tested through 10.4.0), with splunk-add-on-ucc-framework and splunk-appinspect installed into Splunk's bundled Python. Full install steps are on the Splunkbase listing.
I'd love your help testing it 🙏
This is a solo project, so real-world feedback is gold. If you give it a try and spot a bug or think of a useful enhancement, please email me at [email protected] with the details (steps to reproduce, your Splunk/OS version, and any logs help a lot).
As a small thank-you: if you report a valid bug or a beneficial enhancement, I'll happily add your name or username to a Testers section on TA Studio's About page.
Thanks for reading — and thanks in advance to anyone who kicks the tires.