I am trying to create add-ons for splunk enterprise security. is there a developer version of the app , with sample data, that i can install on my local splunk enterprise (like the cloud sandbox trial thats offered). I have a splunk dev license.
See http://dev.splunk.com/view/enterprise-security/SP-CAAAFA6. There's a contact email there that you can use to request a dev copy.
ES includes data samples that can be used to populate the indexes accordingly. To use them, just install the Eventgen app along with ES. Eventgen will automatically begin making events.
Thus, all you need to do is:
There are tons of resources that can be helpful for writing apps so make sure to ask questions here if you run into trouble.
View solution in original post