Who should attend
Advanced Splunk users, administrators, and developers.
Prerequisites
To be successful, students should have a solid understanding of the following modules:
- Fundamentals 1 & 2 (Retired)
- Creating Dashboards
Or the following single-subject modules:
- What is Splunk? (Retired)
- Intro to Splunk (ITS)
- Using Fields (SUF)
- Visualizations (SVZ)
- Leveraging Lookups and Subsearches (LLS)
- Correlation Analysis (SCLAS)
- Search Under the Hood (SUH)
- Intro to Knowledge Objects (IKO)
- Creating Knowledge Objects (CKO)
- Creating Field Extractions (CFE)
- Enriching Data with Lookups (EDL)
- Introduction to Dashboards (ITD)
- Dynamic Dashboards (SDD)
Students should also understand the following modules:
- Advanced Dashboards & Visualizations with Splunk (ADVS)
- System Administration (recommended)
Course Objectives
- Planning Apps
- Creating Apps
- Adding Data
- Enhancing Apps
- Using the REST API
- Packaging Apps
Course Content
This 9-hour course focuses on Splunk app development. It's designed for advanced users, administrators, and developers who want to create apps for Splunk Enterprise and Splunk Cloud. Major topics include planning apps, building data generators, adding data, creating custom search commands and REST endpoints, using the KV Store, app vetting using AppInspect, and app packaging.