Splunk Developer Connection
Package
You don’t have to be a developer to create a Splunk application. Its easy to package your own searches and restyle the Web-based interface.
Learn More »
Build
Splunk's REST API provides methods to build your own application, access IT data from existing applications and integrate IT data into Web pages and Web services.
Learn More »
Embed
Need an embedded engine to collect, organize and secure logs, configuration and metrics? Splunk's flexibility and lightweight footprint makes it an ideal solution.
Learn More »Aggregating Metrics from all your Splunks…
If you found that the new metrics being generated by Splunk on the input (indexing in many cases) and forwarding side to be useful, I am sure you want to aggregate them all in a central location. Well, you can do that by using Splunk's forwarding mechanism itself! Although, it does not matter where you aggregate these metrics, I believe the Read more »
Forwarder and Indexer Metrics
If you were always wondering how much data was being transferred between your forwarders and indexers, we may have some help for you. Splunk now publishes these metrics to metrics.log, which are by default tailed and indexed in "_internal". Forwarding-side Splunk uses a component called TcpOutputProcessor, which is configured using outputs.conf, Read more »
Did you know that your Acitve Directory is just a glorified LDAP?

Microsoft Tube Surfers, Wanted to take a minute to talk about authenticating Splunk against Active Directory. In case you didn't know Active Directory is running on top of LDAP. While the guys up in Redmond do their best to make sure tha you have no need to know LDAP they give you the ability to interface with it over LDAP if you know what you're Read more »
Help Me Help You

Peoples of the Interweb, As one of the Splunk Support Monkeys I am going to try to start a semi-regular series of posts on a topic that is near and dear to me - getting the Splunk community to be able to troubleshoot their issues without the need to reach out to the Support Team. The most important piece of any troubleshooting exercise is getting Read more »
WMI comes to Splunk
The Windows release of Splunk Preview debuts with WMI. So, what is WMI for all you splunkheads out there? It's an OS interface which allows "instrumented components to provide information and notification". WMI gives you the ability to query system instrumentation data such as system performance, event logs, end countless other events that occur Read more »
Splunk Windows Registry Monitor
Hey everyone, just wanted to let you know that a preview release of Splunk just left the docks. http://www.splunk.com/index.php/preview I want to introduce to you one the latest features for Windows Splunk - the monitoring of Windows registry in real time for activity/events, and the indexing and searching these events with Splunk. While working on Read more »
Developer Videos
|View all »May 08, 2008
May 08, 2008
Mar 11, 2008
Mar 03, 2008
Feb 29, 2008