The THOR App includes:
Dashboards
Reports
The THOR Add-on includes:
Event Type Definitions
Field Extractions
Input Definitions
Lookups
Index Configuration
Source Type Configuration
Tags
Transforms
If you use Splunk as a simple Syslog Receiver you have to install the new THOR Add-on and the new THOR App on that system.
If you use Splunk Forwarders to collect your data, you can now deploy the THOR Add-ons on the Forwarders with the Deployment Manager and the lightweight THOR App on the Search Head.
Upgrading from Version 1:
The Add-on does not include the index "thor" anymore. After upgrading version 1 to version 2, you can then create a new index named "thor" with at least the size of the old index and the index and indexed data will reappear. (no warranty; We recommend creating a backup of that index)
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.