Skip to main content
Back to products
FreeAuthoringDashboardsAlerts

Event Builder for Splunk

Drag-and-drop wizards for Splunk dashboard panels, alerts, and saved searches — no SPL muscle memory required.

Overview

Event Builder for Splunk is a visual authoring layer on top of Splunk Web. Operators compose dashboard panels, alerts, and saved searches by dragging fields and conditions onto a canvas; the builder emits the underlying SPL, validates it, and publishes to the chosen app context. Designed for analysts who own outcomes (incident response, SOC reporting) but don't want to memorize the SPL grammar. Free and open-source — install directly from Splunkbase.

Capabilities

01

Drag-drop authoring

Compose dashboard panels and alerts by dragging fields, filters, and aggregations onto a canvas. The builder emits valid SPL behind the scenes — no grammar memorization required.

02

Live SPL preview

Every drag operation updates a read-only SPL pane so the analyst learns the grammar by association, not by ceremony. Toggle to "expert" mode at any time to hand-edit.

03

Component library

Save common patterns (a 24h auth-failure trend, a top-N geo breakdown) as reusable components. Drop one onto a new panel and the underlying SPL resolves contextually.

04

Publishes anywhere

Targets any installed app context with the right capabilities. Outputs land as savedsearches.conf entries on disk, picked up on the next Splunk reload — no manual file plumbing.

05

RBAC-aware

Reads the active user's capabilities and hides actions they're not allowed to perform. Authoring an alert requires `schedule_search`; publishing a panel requires write on the target app — enforced in the UI before the SPL ever reaches Splunk.

06

RSA-PSS signed licenses

Same signed-license model as the rest of the marketplace: licenses carry a 2048-bit RSA-PSS signature verified locally on the customer's install — no SaaS round-trip required to keep working.

Requirements

Splunk
8.2+
Platform
Linux, Windows, macOS
Memory
4GB RAM minimum, 8GB recommended
Storage
300MB available space
CPU
2+ cores recommended