A
action
In Platform, a command that an analyst can run manually or in a playbook in Splunk Mission Control or Splunk SOAR (Cloud). For example, adding a file, comment, or attachment.
In AppDynamics, an automatic response to an event based on a policy. Examples include sending alerts, taking diagnostic snapshots, remediation through scripts, or making a REST API call to integrate with other tools. Actions are customizable.
Related Products: Platform, AppDynamics
Related Terms: connector
ad hoc search
An unscheduled search. Use ad hoc searches to explore your data or to build a search incrementally. Ad hoc searches are most commonly run from the Search bar. You can save ad hoc searches as dashboard panels and scheduled reports.
Related Products: Platform
ad hoc search head
A search head that is configured or designated to run ad hoc searches only, and does not participate in running scheduled searches . An ad hoc search head can be either a standalone search head or a search head cluster member .
Related Products: Platform
ad-hoc risk entry
A manual, one-time adjustment to an object's risk score . You can use ad-hoc risk entries to add to, subtract from, or neutralize risk.
Related Products: Platform
adaptive response action
A type of custom alert action that conforms to the common action model. In Splunk Enterprise Security, you can trigger Adaptive Response actions from correlation searches or on an ad hoc basis when examining a notable event on Incident Review. You can create a custom Adaptive Response action with the Splunk Add-on Builder or by leveraging the cim_actions.py library available in the Common Information Model Add-on.
Related Products: Platform, Enterprise Security
add-on
A type of app that runs on the Splunk platform and provides specific capabilities to other apps, such as getting data in, mapping data, or providing saved searches and macros. An add-on is not typically run as a standalone app. Instead, an add-on is a reusable component that supports other apps across a number of different use cases. Examples of add-ons are the Splunk Add-on for EMC VNX or the Splunk Common Information Model Add-on.
Related Products: Platform
agent
In Platform, a software tool or component that processes and forwards software telemetry to an observability back end, such as Splunk Observability Cloud. In the context of application monitoring, agents instrument applications to collect spans, traces, logs, and metrics. There are two types of observability agents: You can configure Splunk agents for application monitoring (APM), real-time user monitoring (RUM), and infrastructure monitoring using the Splunk Distribution of OpenTelemetry Collector.
In AppDynamics, an agent is code that collects and reports data. Agents can refer to languages (Java, Node.js, Python, etc), machines (hardware and network data), and databases, etc.
In Observability Cloud, an agent is a deployment method where an instance of the Splunk Distribution of OpenTelemetry Collector runs with the application or on the same host as the application. For example, when you configure the Splunk Distribution of OpenTelemetry Collector for Linux, Kubernetes, or Windows, you are using the agent deployment method.
Related Products: Platform, AppDynamics, Observability Cloud
Related Terms: instrumentation, splunk distribution of opentelemetry collector
agent management
A graphical interface built on top of the agent manager that provides an easy way to configure the agent manager and monitor the status of deployment updates. The name has changed from "forwarder management" to "agent management" in version 10.0.0 of Splunk Enterprise. The functionality remains unchanged.
Related Products: Platform
alert
In Platform, an alert is a type of saved search . Alerts run in real time or on a scheduled interval and are triggered when they return results that meet user-defined conditions. When an alert is triggered, it can initialize one or more alert actions .
In AppDynamics, email, SMS, or customized external notification interface that notifies you of a problem or event.
In Observability Cloud, an alert is triggered when the conditions for a detector rule are met. For example, a detector monitoring the number of application requests has a rule that produces an alert if the number is below a static threshold, for example, 20 requests per minute, or above a calculated one, for example, the mean + 3 standard deviations above the number of requests...
Related Products: Platform, AppDynamics, Observability Cloud
alert action
A response, such as an email notification or webhook, to alert triggering or report completion. Alert actions can include search metadata or result details in notifications. Alert actions are knowledge objects with permissions that are configurable separately from those of alerts.
Related Products: Platform
alias
An alternate name that you assign to a field , allowing you to use that name to search for events that contain that field. A field can have multiple aliases. Each alias applies to only one field. An alias does not replace a field in an event or remove it from an event. It is added to the event alongside the field. You can use field aliasing to normalize field names.
Related Products: Platform
Related Terms: tag
allow list
A filtering rule that includes one or more members in a set. For example, you can use allow list rules to tell a forwarder which files to consume when monitoring directories, or you can use allow list rules with the deployment server to explicitly select a deployment client . You can combine allow list rules with deny list rules, which specify which members of a set to exclude, to achieve precise filtering. Deny list rules override allow list rules. The term "allow list" replaces the term "whitelist", which is no longer in use. Both terms refer to the same functionality. In Getting Data In : In Updating Splunk Enterprise Instances :
Related Products: Platform
analytic stories
Actionable guidance for detecting, analyzing, and addressing security threats provided by the Splunk Security Research team. An analytic story contains the searches required to implement the story in a specific security environment, and it provides an explanation of what the search achieves and how to convert the search into adaptive response actions where appropriate.
Related Products: Platform
annotations
Relevant context that you can enrich your risk notables with in Splunk Enterprise Security, such as a specific cybersecurity framework like MITRE ATT&CK, CIS 20, or NIST Controls.
Related Products: Platform, Enterprise Security
application (app)
In Platform, a custom solution running on the Splunk platform that packages specific files and settings to address specific use cases. An app can contain one or more views and can include knowledge objects such as reports , lookups , scripted inputs , and modular inputs . An app sometimes depends on one or more add-ons for specific functionality. An example of an app is the Splunk Enterprise Search app .
In AppDynamics, a named collection of tiers representing a monitored environment. Also referred to as Business Application.
Related Products: Platform, AppDynamics
app key value store
The app key value store (KV store) provides a way to save and retrieve data within your Splunk apps as collections of key-value pairs, letting you manage and maintain the state of your apps and store additional information. With the KV store, you can do the following tasks:
Related Products: Platform
app manifest
The app manifest is a .manifest file generated by the Packaging Toolkit to describe a Splunk app , including dependencies and input groups.
Related Products: Platform
archiving
The action of adding to and maintaining a collection of historical data. In Splunk Enterprise, you can define archiving policy to fit the needs of your organization. You can specify that indexed data be archived according to the size or age of an index .
Related Products: Platform
artifact
Any item in Splunk SOAR (Cloud) or Splunk Mission Control that indicates risk, including risk objects , threat objects , observables , assets , identities , and indicators . Groups of similar artifacts are called entities.
Related Products: Platform
asset
A networked system or device in a customer organization. Splunk Enterprise Security uses machine data such as IP addresses, domain names, NetBIOS names, and machine addresses generated by assets to contextualize systems and associate them with events to identify potential security threats.
Related Products: Platform, Enterprise Security
Related Terms: identity, risk object
attribute
A field associated with the dataset represented by a data model dataset . When using the Pivot Editor , Pivot users select attributes to define tables, charts, and other data visualizations. Every child object in a data model contains attributes that it has inherited from its parent object. Data model objects can contain additional attributes that are extracted fields , calculated fields , and fields derived from lookups .
Related Products: Platform
audit event
An event generated when an audited activity is performed in Splunk Enterprise. The audit event is written to the audit index . Examples of audited activities include search jobs and changes to role-based access controls.
Related Products: Platform
audit index
The index where audit events are stored.
Related Products: Platform
automatic key value field extraction
A type of field extraction that uses the KV_MODE attribute in props.conf to automatically extract fields for events associated with a specific host, source, or source type. Automatic key-value field extractions come third in the sequence of search time operations, before field aliases but after inline field extractions and transform field extractions. Automatic key-value field extractions are on by default and can be configured in props.conf . Automatic key-value field extractions is one of three types of search-time field extractions. See transform field extractions or inline field extractions for more information.
Related Products: Platform
Related Terms: inline field extraction, transform field extraction