icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Keyword
SHA256 checksum (keyword_221.tgz) 131f8339cf6bd7d240f2ef32859a02ea3f98be167d7e949e991d1791a7049ae9 SHA256 checksum (keyword_214.tgz) 3d59d55e17fbabf553311a5f4a7c8996aeaadda55ec487607679e4b68fbecbc5 SHA256 checksum (keyword_213.tgz) 0407b19bd5762f9a10844b4ff4ecbbf156041d4dd7efc409080dc16c30e324d4 SHA256 checksum (keyword_21.tgz) c8028083017b9779f54b5c79bd2777adecd806fb36518374e4685c1f20765f90 SHA256 checksum (keyword_202.tgz) a68a54b554701db025da5d28c890027125063afc5d56fa36dac3f8e582b46e1d SHA256 checksum (keyword_201.tgz) 6edb0f7e5da56f6bb8b33ec4c94e62fe1d1dca7abe30d8a7dd03a07145163efe SHA256 checksum (keyword_18.tgz) 387ca287f10651d15ce49042771ee7d725da05bd0ec68ad0b664bcc722e335fb SHA256 checksum (keyword_17.tgz) 7b49ac3a261aa0c8609757d9907ed8918df7fcbcfdc0bfbe17c415f8844d796b SHA256 checksum (keyword_16.tgz) 10a5ae251e01370599bfd5cf256e93823545f94aa999c8c94debfe05d4ab73ee SHA256 checksum (keyword_15.tgz) f842f4f802a9c864c5cd2ee81b082e7dcc40c5d79130f3e4603992569b350189 SHA256 checksum (keyword_14.tgz) cc02c6757eb916fedd67188e59c4f382f32ce852b281a6b01974e7dc50c1083b SHA256 checksum (keyword_13.tgz) cbd83112c1daf63bf1499920131c204b8fbc1234b81cbfc481d8e9f7b48d06ff SHA256 checksum (keyword_122.tgz) eec6c7b3cc13334e3fa1b463ebc8844778d627015ca9964141388eadfe99a114 SHA256 checksum (keyword_121.tgz) 39d417afdf2dc8d10dafedaed1144afdf5c186835cac0c77c4ad4fa39374e0b7 SHA256 checksum (keyword_12.tgz) 65a72667653cf8f2dc40018b331c0b87b66cce796147ae645b5c72f573175e99 SHA256 checksum (keyword_11.tgz) e901ace7a5b48638f00d6c58f0c2cb4772e3c7146fcb732d6e2fc551eea62753 SHA256 checksum (keyword_10.tgz) 8ab3c32afb32706cb2f904c6dde8e83873b40a59523c09cd76af9802510a8fd2
To install your download
To install apps and add-ons from within Splunk Enterprise
  1. Log into Splunk Enterprise.
  2. On the Apps menu, click Manage Apps.
  3. Click Install app from file.
  4. In the Upload app window, click Choose File.
  5. Locate the .tar.gz file you just downloaded, and then click Open or Choose.
  6. Click Upload.
  7. Click Restart Splunk, and then confirm that you want to restart.
To install apps and add-ons directly into Splunk Enterprise
  1. Put the downloaded file in the $SPLUNK_HOME/etc/apps directory.
  2. Untar and ungzip your app or add-on, using a tool like tar -xvf (on *nix) or WinZip (on Windows).
  3. Restart Splunk.
After you install a Splunk app, you will find it on Splunk Home. If you have questions or need more information, see Manage app and add-on objects.

Flag As Inappropriate

splunk

Keyword

Splunk Cloud
Overview
This app presents a form where a user can type a keyword such as error and find top/timecharts of the results by source, sourcetype, and host on a dashboard. The same search could be used for finding last week vs. this week comparisons, to see if there are any sources, sourcetypes, or hosts that go above standard deviation plus the average count of occurrences, and to see a donut chart dashboard distribution of different keywords by metadata. See the README for more details.
Look under the Dashboard Menu for the Rare, Rare Punctuation, Cluster to find Anomalies, Outlier, Slope, Predict, Timewrap, Abstract of Events, Easy Button to find errors, and Baseline Forms.

Release Notes

Version 2.2.1
March 22, 2024

Removed local meta file and removed checksum from app.conf to make this Splunk cloud compatible.

Version 2.1.4
June 3, 2021

Removed JS files for Jquery compliance. Added version="1.1" in all forms and dashboards for Splunk 8.2. Added approved Autobahn logo to indicate this can be used in Splunk Cloud.

Version 2.1.3
Jan. 23, 2020

lowercase x for static/appIcon_2x.png spelling to pass appInspect

Version 2.1
Oct. 9, 2018

Added Introduction Page and moved top dashboard to dashboards. If you have Module error issues with the Donut Chart, try restarting Splunk.

Version 2.0.2
July 25, 2017

Updated |REST call to |eventcount to get index names for each dashboard's index field. Thanks Jay Slay.

Version 2.0.1
July 17, 2017

fixed bug with duplicate indexes (dedup title. Thanks Jay Slay). Also, changed Easy Button to Easy Triage and updated description.

Version 1.8
March 14, 2016

Added Hutch's Icons; Added Abstract Dashboard. Took quotes away from keyword_field in search template so that you can search for anything before the | symbol.

Version 1.7
Jan. 9, 2015

Updated Top and Rare Punct Dashboards to use stats, count, and head 10

Version 1.6
Sept. 18, 2014

Added rare punct. Changed icon

Version 1.5
May 29, 2014

Keyword Rare Punctuation - finds rare events based on punctuation

Version 1.4
May 28, 2014

Added Rare Dashboard

Version 1.3
Feb. 6, 2014
Version 1.2.2
April 8, 2013

Changed Donut Chart Dashboard to now split by top 10 host, source, or sourcetype.

Version 1.2.1
April 3, 2013

Donut chart now splits by sourcetype only as the results are same if you used host or source, so I just picked sourcetype.

Version 1.2
April 3, 2013

Added Ron Naken's Donut Chart (new dashboard) and changed stdev to stdevp in Outliers Dashboard.

Version 1.1
March 22, 2013

Added Slope and Predict Dashboards.

Version 1.0
March 19, 2013

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.