What are Splunk apps (1)
Collection of files containing data inputs, UI elements, knowledge objects
What are Splunk apps (2)
Apps allow different workspaces for specific use cases or user roles to co-exist on same Splunk server
Search and reporting app
Default interface for searching and analyzing data
Allows user to create knowledge objects, reports, dashboards
Host
Unique identifier where events originated (host name, ip, etc)
Source
Name of stream, file or other input
Sourcetype
Specific data type or data format. Parser to parse known log format