Reflections on a Splunk developer’s journey : Part 1
It seems like only yesterday
…that I was writing my first Splunk App. It was the openness and extensibility of the Splunk platform that attracted me to this pursuit in the first place, and when I discovered the thriving community on Splunkbase (now called Splunk Apps / Answers), I just had to contribute. 11,000+ downloads across 9 different freely available community offerings later, I am feeling somewhat reflective. So in this 2 part blog series I want to share with you some of my lessons learned from developing and supporting Splunk community Apps/Add-ons (part 1) and then some musings on why you should consider developing Splunk Apps/Add-ons yourself and contribute to the Splunk developer ecosystem (part 2).
Some lessons learned…
Add an icon to your app or add-on
The “icon” has become a de-facto standard element of content description; it helps users to discover relevant content with just a quick look and helps your content to stand out from other apps. Until now, due to packaging limitations, only content hosted directly on Splunk Apps supported the display of an icon.
As part of the user experience improvements we’ve made to Splunk Apps, we are introducing a new feature that allows you to attach an icon to externally hosted apps and add-ons.
To add an icon to your app: visit your app’s Edit page and look for the new option there.
Drag and drop your new icon into the box and click Update.
Based on my observations, apps …
Splunk Alerts and Charts on Your iPhone
Now Splunk is EVERYWHERE!
Push alerts and charts to your cellphone from your Splunk servers, when you’re on the beach. Get your Splunk data conveniently on the go. Available now!
EVERYWHERE is a one-way data push from firewalled splunk servers to mobile devices, via a cloud-based service run by Splunk or your own organization.
Not an official Splunk product, but a really useful skunkworks project.
Announcing Splunk ODBC Driver
Most people using Splunk Enterprise today would probably agree that they’re getting valuable insights from the machine data their applications, technology and devices continuously generate. Splunk helps thousands of organizations use their data to drive higher service uptime, prevent cyber-security attacks and drive completely new and valuable insights for their business.
IT teams know the value of machine data and leverage it every day, but what about the other users in your organization. How do you share that data with them, without always being the go-to guy? What about users in your organization that are already using an analytics tool such as Microsoft Excel or Tableau Desktop? How can they start leveraging the data in Splunk Enterprise, without asking IT …
Comparing week-over-week results
Comparing week-over-week results is a pain in Splunk. You have to do absurd math with crazy date calculations for even the simplest comparison of a single week to another week.
No more. I wrote a convenient search command called timewrap that does it all, for arbitrary time periods, over *multiple* periods (compare the last 5 weeks). Compare week-over-week, day-over-day, month-over-month, quarter-over-quarter, year-over-year, or any multiple (e.g. two week periods over two week periods). It also supports multiple series (e.g., min, max, and avg over the last few weeks).
After a ‘timechart’ command, just add “| timewrap 1w” to compare week-over-week, or use ‘h’ (hour), ‘m’ (month), ‘q’ (quarter), ‘y’ (year).
I’m done my part. Now do yours — download …
Experimental App Helps Find Other Splunkbase Apps
I’ve recently developed a Splunk app called “splunkbase“. It looks at your Splunk installation and suggests apps on splunkbase.com relevant to your data. It analyzes your indexed data, as well as data in your file system not yet indexed. It also suggests apps based on what other Splunk users have installed at similar installations — sort of like how Amazon will suggest items to purchase based on what other users similar to you have purchase.
The app is simple to run — it’s just one dashboard, with several reports that suggest apps.
Security: At no time is any of your data uploaded or forwarded on. The signatures of all free splunkbase apps are included with this app so …
The 2nd Annual APAC Partner Kick Off
Before we knew it, it is almost time for our 2nd annual APAC partner kick off that will fall on 19th till 21st March 2013 at magnificent Bali, Indonesia. As a preview to all the partners who will be attending this kick off with us, we have lined up a series of rock solid business and technical tracks that will definitely keep their time away from the beaches and bars. I’m sure the partners will gain tremendous values out from these three days.
There are close to 30 tracks that will be delivered, and topics range from global deployment considerations to Splunk modular inputs and SDK to even a rare chance to hear what our legal has to say about …
Splunking Exchange in a Simple XML World
With the release of Splunk 5.0, the Simple XML language we use to define the dashboards and forms for an app was greatly extended. So, we were given a challenge – could a reasonably complex app, such as the Splunk App for Microsoft Exchange – be represented using only Simple XML?
Splunk App for Active Directory and the Top 10 Issues
I work a lot with the various people who plan, deploy and support the Splunk App for Active Directory. Some issues come up quite frequently and I thought it would be a good idea to give you a roadmap of things to check as you deploy your environment. I’ll go through the issue and how to check for it so that you can make your roll-out as smooth as possible.