Splunk Developer Connection

package

Package

You don’t have to be a developer to create a Splunk application. Its easy to package your own searches and restyle the Web-based interface.

Learn More »

Build

Splunk's REST API provides methods to build your own application, access IT data from existing applications and integrate IT data into Web pages and Web services.

Learn More »

Embed

Need an embedded engine to collect, organize and secure logs, configuration and metrics? Splunk's flexibility and lightweight footprint makes it an ideal solution.

Learn More »
Developer Perspectives
|View all »

Aggregating Metrics from all your Splunks…

If you found that the new metrics being generated by Splunk on the input (indexing in many cases) and forwarding side to be useful, I am sure you want to aggregate them all in a central location. Well, you can do that by using Splunk's forwarding mechanism itself! Although, it does not matter where you aggregate these metrics, I believe the Read more »

Posted by: inder on May 15, 2008

Forwarder and Indexer Metrics

If you were always wondering how much data was being transferred between your forwarders and indexers, we may have some help for you. Splunk now publishes these metrics to metrics.log, which are by default tailed and indexed in "_internal". Forwarding-side Splunk uses a component called TcpOutputProcessor, which is configured using outputs.conf, Read more »

Posted by: inder on May 15, 2008

Did you know that your Acitve Directory is just a glorified LDAP?

Microsoft Tube Surfers, Wanted to take a minute to talk about authenticating Splunk against Active Directory. In case you didn't know Active Directory is running on top of LDAP. While the guys up in Redmond do their best to make sure tha you have no need to know LDAP they give you the ability to interface with it over LDAP if you know what you're Read more »

Posted by: matt on May 12, 2008

Help Me Help You

Peoples of the Interweb, As one of the Splunk Support Monkeys I am going to try to start a semi-regular series of posts on a topic that is near and dear to me - getting the Splunk community to be able to troubleshoot their issues without the need to reach out to the Support Team. The most important piece of any troubleshooting exercise is getting Read more »

Posted by: matt on Apr 30, 2008

WMI comes to Splunk

The Windows release of Splunk Preview debuts with WMI. So, what is WMI for all you splunkheads out there? It's an OS interface which allows "instrumented components to provide information and notification". WMI gives you the ability to query system instrumentation data such as system performance, event logs, end countless other events that occur Read more »

Posted by: igor on Apr 29, 2008

Splunk Windows Registry Monitor

Hey everyone, just wanted to let you know that a preview release of Splunk just left the docks. http://www.splunk.com/index.php/preview I want to introduce to you one the latest features for Windows Splunk - the monitoring of Windows registry in real time for activity/events, and the indexing and searching these events with Splunk. While working on Read more »

Posted by: ledio on Apr 28, 2008

close

Flash required to play this video.

Click here to download the free Flash Player.

Description:

Permalink: