Splunk’s New Web Framework, Volkswagen’s Data Lab, and the Internet of Things.

There are many incredible features in Splunk 6. Pivot, Data Models and integrated maps really stole the show at .conf2013. But I really have to give credit to our developer team in Seattle for the massive leap forward in user interface possibilities with the addition of the integrated web framework, which is included in Splunk 6 but is also available as an app download for Splunk 5.

In the midst of all that Splunk 6 excitement at .conf, I was introduced (at the Internet of Things pavilion) to the team at Volkswagen Data Lab, and had some great discussions with them about their interest in using Splunk as a  platform for the management, analysis, and visualization of data from …

» Continue reading

Custom Icons in Splunk 6 Tables

“Daddy. DADDY! We’re out of Sriracha. Does Costco sell Sriracha? Can you go get some before you start working today?”

That was my five-year-old son at breakfast this morning, after he turned the Sriracha bottle upside down and banged the heck out of the bottom of the rooster-adorned bottle with his tiny fist, trying to get the last bits of the dark-red chili sauce deposited onto his scrambled eggs.

While I’m certain we will solve the 2014 Sriracha Crisis at the Brodsky household, the whole episode reminded me of a question (stick with me, you’ll see why) that a Splunk customer asked me a few months ago, which went something like this:

“When creating a dashboard in Splunk 6,

» Continue reading

Using Bootstrap Modal with Splunk Simple XML

While working on a performance dashboard recently, I wanted an area to further explain the performance metric currently being displayed without taking up too much screen real estate. In the end, I ended up using a Bootstrap modal dialog to display the metric details when a user clicks an information icon. Here is the end result:




Step 1 – Add the Bootstrap modal markup to your dashboard

Pulling the syntax directly from Bootstrap (http://getbootstrap.com/javascript/#modals), this is what the Simple XML looks like:


<row grouping=”2”>
    <chart id=”chart1”> … </chart>
        <a href="#" id="btn1" class="btnModalInfo" data-toggle="modal" data-target="#desc1">…</a>
        <div class="modal fade" id="desc1">
            <div class="modal-dialog">
                <div class="modal-content">
                    <div class="modal-header"></div>
                    <div class="modal-body">…</div>
                    <div class="modal-footer">…</div>


» Continue reading

Add an icon to your app or add-on

The “icon” has become a de-facto standard element of content description; it helps users to discover relevant content with just a quick look and helps your content to stand out from other apps. Until now, due to packaging limitations, only content hosted directly on Splunk Apps supported the display of  an icon.

As part of the user experience improvements we’ve made to Splunk Apps, we are introducing a new feature that allows you to attach an icon to externally hosted apps and add-ons.

To add an icon to your app: visit your app’s Edit page and look for the new option there.

Screen Shot 2014-02-03 at 2.03.15 PM

Drag and drop your new icon into the box and click Update.

Based on my observations, apps …

» Continue reading

Splunk Alerts and Charts on Your iPhone

Now Splunk is EVERYWHERE!

Push alerts and charts to your cellphone from your Splunk servers, when you’re on the beach.  Get your Splunk data conveniently on the go.  Available now!

EVERYWHERE is a one-way data push from firewalled splunk servers to mobile devices, via a cloud-based service run by Splunk or your own organization.

Go here:  Get the app for your Splunk server, sign up for the cloud services, and get the iPhone app.

Not an official Splunk product, but a really useful skunkworks project.

» Continue reading

Add a Tooltip to Simple XML Tables with Bootstrap and a Custom Cell Renderer

I recently created a dashboard that displayed some information from the Windows Event Logs in a table.  The “Message” field was important, but took up a lot of screen real estate.  Since a lot of Bootstrap is built right into Splunk 6, adding a little JavaScript allowed me customize the display to show the “Message” field when hovering over some text or icon.

Here is the result:

Table with Bootstrap Tooltip


Continue reading for the explanation or just go download the example on GitHub.

Step 1 – add custom JavaScript and CSS to your form/dashboard

First things first – tell your dashboard or form that it will process additional JavaScript and CSS (optional).

<form stylesheet="app_crash.css" script="app_crash.js">

The .css and .js files should …

» Continue reading

The Splunk App for Unix 5.0 is finally here!

| history | search app=”*nix”

Those of you who have been Splunk users for more than 4 years remember the glorious launch of the original Splunk App for Unix.  Back in those days, the app shipped with the core product alongside the Splunk App for Windows and had some pretty cutting edge features, including knowledge, dashboards, and saved searches with out-of-the-box email alerts (we’re still sorry, Paul S.).

Well, it took a while for us to follow up that triumphant release, but wait no longer: the new app is finally here!  And oh, what’s better, the app is FREE!!!  Read on for the technical details of the app.…

» Continue reading

Splunking jQuery Conference: drive user experience online and on site!

jQuery Portland 2013 Conference

Last June, jQuery Foundation held their conference in beautiful Portland, Oregon. As a Diamond Sponsor, we wanted to build something that would be beneficial to the jQuery community part of our Splunk4Good initiatives. What’s better than Splunking the entire conference?

To see the end result, check out this interactive infographic showcasing Splunk-powered web analytics applied to the conference website. The complete Splunk dashboard can be found here.

The goal is to capture client-side data (e.g. pageviews, link/button clicks, hovers), and build powerful analytics & visualizations in order to tackle the following business questions:

  1. Which topics are visitors most interested in?
  2. What are the top traffic sources for visitors who purchase tickets?
  3. How are visitors interacting with the site, including
» Continue reading

Welcome to the new Splunk Apps site!

Hi All –

Many of you are familiar with Splunkbase, the site that has been host to both Splunk Answers Q&A and Splunk Apps. To date, Splunkbase has been a very popular resource, serving thousands of visitors daily. However, we’ve heard your feedback — the combination of the two was somewhat confusing and suboptimal. We listened, and what we’re delivering today is the result of your feedback.

I’m proud to announce the release of the new Splunk Apps site — a place to discover new content to extend the power of your Splunk deployment!

Our redesign and relaunch of the Splunk Apps site has two major goals—to improve the new content discovery experience and to enable our developers to …

» Continue reading

New Keyword App

One of the most common requests I get from new customers is that they want to centrally collect all their machine generated time series data and search for a keyword like error or RuntimeException. Obviously Splunk can do this. Then, the next set of questions concern things like give me the top hosts or applications producing this keyword, show me a baseline of last week vs this week for this keyword, show me a slope line on the trend for this or any keyword(s), find outliers that go beyond the average occurrences for the keyword and then try to predict what may happen in the future.

To answer these questions and then some, I’ve created an app template that …

» Continue reading