Splunk Enterprise

Need to present a use case for applications

imamsplunk
New Member

Hi, I'm new to splunk. My management has asked to present a use case specific to applications. It could be generic and specific to any particular application. I'm failing to see much use cases for splunk related to applications. Appreciated if someone kindly assist me with some use case.I'm using a splunk enterprise trial version. Thanks .

Tags (1)
0 Karma

snowmizer
Communicator

Splunk by itself is great for getting data into one place for viewing. Splunk will try its best to extract fields it sees but doesn't always get everything. Also, dashboards that provide value related to a particular data source (e.g. web proxy logs) don't exist by default in Splunk. Applications provide the following functionality:

  1. Knowledge objects to parse the data (field extractions, eventtypes that classify data into types (e.g. authentication events))
  2. Dashboards to view the data in a meaningful way
  3. Some applications provide modular inputs to pull data from a particular source into Splunk

To do this yourself you will find the task to be daunting. Applications make that easier. If you download and install an app in your Splunk environment you may find that there is some tweaking that will need to be done (e.g. specifying what index your data resides). Splunk applications allow the end user to customize an app to fit in their environment. Apps aren't compiled. You have access to all of the Python scripts (if there are any) and configuration files.

Bottom line applications (if written correctly) can make your life simpler.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...