December 19, 2025
Data Dictionary App
The Data Dictionary App contains a script which adds an _meta field dd= for all included deployment apps in /etc/apps or /etc/system (defaults to all apps). The Data Dictionary App should be used in conjunction with the Data Dictionary Add-on to maintain an up to date Data Dictionary showing which input apps are sending through what data.Built by Jade BujeyaSplunk Enterprise, Splunk Cloud
Platform Version: 10.1
Log in to rate this app
The Data Dictionary App contains a script which adds an _meta field dd= for all included deployment apps in /etc/apps or /etc/system (defaults to all apps). The Data Dictionary App should be used in conjunction with the Data Dictionary Add-on to maintain an up to date Data Dictionary showing which input apps are sending through what data. Please note: • DO NOT change the name of the app or any internal files. • This app/add-on will increase the size of .tsidx files and includes a dashboard containing an index=* search which defaults to the last 15min. BEWARE! • The script uses btool to generate a list of all the apps containing input.conf files. If you have an input stanza spread across 5 apps (for some reason) only one of those apps will be listed in your data dictionary. As of version 1.0.0: • If you wish to change the frequency with which the script is run, you must do so inside the script.py file itself. • If you wish to change the list of excluded apps, you must do so inside the script.py file itself. Please splunk responsibly.
Log in to report this app listing.