Splunk Enterprise Security

Splunk enterprise security add-on nomenclature

RiccardoV
Communicator

Hi guys,
I am developing an addon for Splunk ES and I'm a little bit confused about the name I have to give to the folder of that addon.

It seems (as here) that I have to name the folder as TA-APPNAME, but under the Splunk ES apps folder I have some other addons named as Splunk_TA_APPNAME (Splunk_TA_windows, Splunk_TA_mcafee..).
Which is the correct one?

And another question: I see that I have many other kind of pattern in my apps directory, as SA-, DA-ESS-. What are they?

thanks!

1 Solution

esix_splunk
Splunk Employee
Splunk Employee

Splunk supported TA's are taking on the name Splunk_TA_appname, and the SA / DA names are based on the functionality of the ES app as described in the documentation at :

http://docs.splunk.com/Documentation/ES/latest/Install/ESArchitecture

You can name your's both TA-appname or Splunk_TA_appname and it will get imported.

View solution in original post

miteshvohra
Contributor

Splunk Docs link for "Naming conventions for apps and add-ons on Splunkbase" : http://docs.splunk.com/Documentation/Splunkbase/latest/Splunkbase/Namingguidelines

Mitesh.

RiccardoV
Communicator

thanks but it doesn't answer to my question 🙂 I was asking about the name of the folder, not the app/addon name

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Splunk supported TA's are taking on the name Splunk_TA_appname, and the SA / DA names are based on the functionality of the ES app as described in the documentation at :

http://docs.splunk.com/Documentation/ES/latest/Install/ESArchitecture

You can name your's both TA-appname or Splunk_TA_appname and it will get imported.

RiccardoV
Communicator

thanks a lot for your fast answer. What does it mean "splunk supported TA"? It means that if I'm developing an addon by myself without Splunk "collaboration" I should name it as TA-*, right?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Any app with the TA-appname or Splunk_TA_appname is automatically imported into ES. Additionally, Splunk supported means the TAs released and officially supported via support contracts with Splunk.

0 Karma

RiccardoV
Communicator

Thanks a lot 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...