2.3 Splunk Apps

Key Takeaways

  • A Splunk app is a packaged workspace of views, searches, dashboards, and configurations for a use case.
  • Add-ons typically focus on knowledge/inputs for specific data sources and often have little or no UI of their own.
  • The Search & Reporting app is the primary User workspace for ad hoc search, reports, and dashboards.
  • Users switch apps from the app bar; knowing which app you are in changes menus and default views.
Last updated: August 2026

Topic 1.3 — Define Splunk apps

In Splunk, an app is a packaged collection of configurations and UI that supports a particular set of tasks. Apps can include dashboards, views, saved searches, navigation menus, and other knowledge. When you log into Splunk Web, you are always "in" an app context — even if you barely notice the label.

Apps vs add-ons

Users (and exam writers) often confuse apps with add-ons. Use this contrast:

ConceptTypical purposeUI presenceUser mental model
AppEnd-to-end workspace for a use caseOften rich: dashboards, nav, search views"Where I work"
Add-onSupporting content for data/source types (inputs, extractions, and related supporting knowledge)Often minimal or none"Helps data work correctly behind the scenes"

You do not need Power User-depth CIM knowledge here. Remember the User-level distinction: apps are workspaces; add-ons commonly extend data handling without being the place you spend your day clicking.

Exam trap: Saying add-ons always include full dashboard suites, or that apps never contain knowledge objects. Apps frequently contain searches and dashboards; add-ons frequently do not emphasize UI.

The Search & Reporting app

For Splunk Core Certified User, the most important app is Search & Reporting. This is where you:

  • Run ad hoc searches in the search bar
  • Use the time range picker and timeline
  • Inspect events and fields
  • Save results, reports, and alerts (subject to permissions)
  • Build and open dashboards associated with that app context

If a question asks where a User typically runs a search, Search & Reporting is the default correct workspace — not the license manager UI, not a random unused app, and not the forwarder host.

Why apps matter on the exam

  1. Navigation: The app bar (app menu) lets you switch apps. Menus and landing pages change with the app.
  2. Scope of objects: Saved reports and dashboards often live in an app. Knowing your app context helps you find what you saved.
  3. Permissions boundary (conceptual): Apps help organize who sees what; deep ACL design is Admin/Power User territory, but Users should know objects are app-aware.

Working example

Imagine your deployment has:

  • Search & Reporting — your daily investigation app
  • A business-specific app with executive dashboards
  • Several add-ons that help onboard Cisco or cloud logs

As a User preparing for Core certification, you spend most study hours in Search & Reporting, occasionally opening another app's dashboard when a question or lab references it. You rarely "open an add-on" as a workspace because many add-ons are not built that way.

Installing and finding apps (User awareness)

Admins typically install apps from Splunkbase or deploy them with configuration management. As a User:

  • You should recognize that apps can be added to a Splunk instance
  • You should know how to switch apps once they exist
  • You should not prioritize Admin install procedures as primary study

If an exam item mentions Splunkbase, think "source of apps/add-ons," not a User daily task.

Search & Reporting layout preview (ties to 1.5)

Inside Search & Reporting you will repeatedly use:

  • Search bar and time range picker
  • Events tab / Statistics / Visualization tabs (depending on search type)
  • Fields sidebar
  • Job controls

Domain 1.3's job is to place that workspace inside the app concept. Domain 1.5 will walk the chrome (app bar, Settings, layout) in more detail.

Common User mistakes with apps

  • Creating a report in App A, then hunting for it while App B is selected
  • Assuming every Splunkbase package is a full interactive app
  • Confusing "default app" preference (user setting) with "only app installed"
  • Thinking Search & Reporting is optional for User certification — it is central

Checklist before you leave this topic

  • Define app in one sentence as a packaged workspace of configs/UI for a use case.
  • Contrast add-on as supporting content often without a full UI.
  • Name Search & Reporting as the primary User search app.
  • Explain that switching apps changes navigation and where you look for dashboards/reports.

App context and permissions (User-safe view)

You do not need to design roles for the User exam, but you should expect this pattern:

  1. An object (report, dashboard, alert) is created in an app.
  2. Sharing settings decide whether others can see it (Private, App, All Apps — exact labels vary by version/permissions).
  3. If your role cannot see another app, you will not see that app's private objects either.

When troubleshooting "missing" content, check app first, then permissions with an admin if needed. Jumping straight to "Splunk is broken" is a User anti-pattern.

Search & Reporting vs other apps — decision table

NeedGo to
Ad hoc investigation with the search barSearch & Reporting
A prebuilt executive dashboard your team publishedThe custom app that owns that dashboard
Data onboarding packages with little UILikely an add-on (Admin installs; you consume the resulting fields/events)
License usage screensLicense-related UI (not your daily search home)

Hands-on micro-lab

  1. Note your current app name in the app bar.
  2. Run a simple search and save it as a report named with today's date.
  3. Switch to another accessible app (if any), then switch back.
  4. Confirm you can still locate the report under the original app context.

That five-minute loop locks Domain 1.3 better than rereading definitions. The exam rewards people who have actually switched apps and noticed the menu change.

Next, Domain topics 1.4 and 1.5 cover personal preferences (time zone, default app) and the basic navigation chrome that surrounds every search you run.

Test Your Knowledge

Which app is the primary workspace for ad hoc searching on the Splunk Core Certified User exam?

A
B
C
D
Test Your Knowledge

How do Splunk apps typically differ from add-ons at a User level?

A
B
C
D
Test Your Knowledge

You saved a dashboard yesterday but cannot find it today. Which User-level check should you try first?

A
B
C
D