Splunk App and Saved Searches
Splunk apps are a way for you to separate your data, searches, reports, and dashboards into separate areas where you can then configure who can access what. Splunk provides a large ecosystem to help third-party developers and companies provide these apps to the general public.
We mentioned earlier in this chapter that Splunk also provides "SplunkBase" for approved apps that have been certified for users by Splunk, such as apps for Cisco Network Devices. It doesn't need to be an approved app for it to be available for use on your system. Splunk allows you to create apps of your own, and if you need to, you can distribute them in a packaged file across to users who wish to use them. The whole point of Splunk apps, dashboards, and saved searches is to reduce the amount of work that is duplicated, as well as providing information to non-technical users when needed.
The following exercise will provide you with some hands-on experience...