icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Search Catalog
SHA256 checksum (search-catalog_120.tgz) f6dcdd4288fb1fedacbe9db2ccc1d110da1c40936fa47570b9bd53d24664b553 SHA256 checksum (search-catalog_112.tgz) 54ee451436fe5c9eeaf28ee53d7c5a1932d9ae29b8110c7184dd558b5bb9c6bb SHA256 checksum (search-catalog_111.tgz) 6ac5d52f6a5ec4e48421c7409d0c32c0a92b86921538f1c913f93c58ef027222
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Search Catalog

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
Have you ever wanted a centralized location to direct users to so they can find what they need? Example: What special index do we store our firewall data? This app provides a simple interface to centrally locate information on where data is stored in a given Splunk instance.

Search Catalog

The intent of this app is to provide a simple interface for sharing knowledge in Splunk through editing a simple CSV file, the app can generate a set of standard dashboards and navigation.

Description and Use-cases

Have you ever wanted a centralized location to direct users to so they can find what they need? Example: What special index do we store our firewall data? This app provides a simple interface for both administrators (to catalog data locations) and users (to find the data they need).

Depending on how Splunk is managed, finding data for a new (or even experienced) user can be challenging. The primary use-case of this app is for a Splunk adminstrator to be able to easily catalog (using a CSV file) where specific types of data (that an end user may have interest in) would be found on the given system and provide the end user an interface to quickly find this data (using Splunk’s built in menu system). Even though there exists the CIM, not all data is CIM compatible, nor is a user necessarily familiar with CIM. This can be especially helpful as new data types become available in Splunk that are not complying with CIM.

How to use

Adminstrator

The app comes with an example CSV lookup file with sections, subsections and searches that should be universal. Using the built-in dashboard to add searches, an administrator can fill the catalog with the necessary content for the users. The CSV can also be edited directly or the app contains links to open the file in the Lookup File Editor app (https://splunkbase.splunk.com/app/1724/ requires 2.x), especially useful if searches need to be deleted. While it is not required, it is recommended to fill out the Notes section of each search so that both the generated dashboard will give some helpful context and a user may find the search based on keywords in the notes (using the search dashboard called “Not Sure Where to Look?"). The administrator should either copy the example CSV found in the samples directory to the lookups directory or use the add searches dashboard to create the file. The add searches dashboard includes help information.

Once the lookup/CSV file has been populated with searches, the app has a custom command to generate menus, dashboards, and links based on the data in the lookup (“Generate Dashboards”). Each search can be given it’s own dashboard with notes, events, and some basic info and statistics of it’s primary fields. There are also links to open the search up in the normal search window (in the regular Search app not the Search Catalog) from the dashboard as well as a time range picker. The other option is send the user to a specific link (like an existing dashboard) or convert the search into a link and skipping the generated dashboard and only adding a menu item.

Each generated dashboard includes a panel titled “Most Populated Fields”. If an admin wants to filter specific fields out of this (i.e. date_*) the most_populated_filter.csv file must be created and filled. Similar to the search_catalog.csv the app contains an example most_populated_filter.csv, and again the administrator should either copy the example CSV found in the samples directory to the lookups directory or use the add searches dashboard to create the file.

End User

From the Welcome screen a user is introduced to the number of searches that exist in the search catalog along with an idea of how those searches are dispersed. The user is given instructions to browse through the Search Catalog’s menus, search or see what are the latest searches that have been added.

Release Notes

Version 1.2.0
May 2, 2020

Cosmetic updates. Updated for Python 2 and 3 compatability. Updated to latest splunklib. Added new ability to add or generate a link from the config file (instead of generating a dashboard), adds the link in the navigation. Added new examples in the sample lookup file. Added ability to add search or link to top level menu instead of under a section. Added help panels for add search dashboard.

Version 1.1.2
Feb. 1, 2018

Minor update for Splunk Certification requirement and code formatting updates. Fix searching to not return folders.

Version 1.1.1
Jan. 31, 2018

Fixed Most Populated Fields panel to not max out on quantity of distinct values. Fixed naming scheme for dashboard to seperate correctly. Fixed "Not Sure Where to Look?" and "Most Recent Added Searches" dashboards as they were not creating correct links to dashboards anymore.


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.