Modules

Splunk's Simplified XML is basically XML with JavaScript at the backend. Splunk lovingly refers to these JavaScripts as extensions when one is needed for a specific function. In simplified XML, they have some basic modules that someone can access in order to create a dashboard with ease by pointing and clicking, instead of having to know all the advanced XML to render a page.

Each module has a series of tokens that can pass data values down to an underlying search, or even be put in a link to a URL. These become very important in Splunk development in order to display the appropriate information and filter on the click of a button.

There are a few different module types.

Data input

Data input modules are things that add or filter data within ...

Get Splunk Best Practices now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.