Install a Splunk application by unpacking it into your $SPLUNK_HOME/etc/bundles directory. Once you've configured it (according to the instructions in the following sections), restart your Splunk server to load it into your Splunk instance.
Once you have an application installed, it's a good idea to look through it to make sure it works for your data. The sections below address what you may need to change, and where to go to find help on how to change it.
There are some general issues that apply no matter what aspect of the application you want to customize:
See both the User manual section on event types and the Administrator manual section on introductory administrator event types, if you haven't already. Other items of interest include:
Customize an application's fieldsSee the User manual section on fields and the Administrator manual section on fields, if you haven't already. Other items of interest include:
Customize an application's inputsSee the administrator input docs if you haven't already. Other items of interest include:
Customize an application's saved searches and alertsSee the User manual section on saved searches and alerts and the Administrator saved searches section, if you haven't already. Other items of interest include:
Customize an application's reportsMuch of the material on reporting is entwined with that of saved searches and alerts. In addition to this, see the user documentation on reporting.
Comments
No comments have been submitted.