So what is
Splunk? At its core
Splunk is a search engine. It was designed to allow any data from an infrastructure device to be indexed and searched. Any output from applications, servers and network devices can be “eaten” by
Splunk. However,
Splunk has become more than just a standalone product. The current 3.x series of the product has opened up the internal API and exposed it to allow outside development of new applications on top of the
Splunk core. This post is going to touch on some of the capabilities available to developers looking to get even more out of their
Splunk installation.
I am going to be discussing two elements of
Splunk that a user can customize and enhance in the current product release: Spunk UI customization and RESTful applications.