Developing on SSE
Welcome to the Development section for Splunk Security Essentials. This section is only relevant to partners or internal users who are developing on the SSE platform. In particular, for partners, there was a major effort to push all relevant documentation to the Partner Integration guide, with the SSE Schema as a reference. To support transparency and aid troubleshooting, the internal documentation of SSE has also been stored here. As all of the SSE source code is publicly accessible (governed by the SplunkBase license), you can troubleshoot advanced issues on your own.
- Partner Integration
- SSE Schema
- Adding Content
- ShowcaseInfo.json Generation
- Key Files
Find out Why, and How to integrate with SSE using our detailed docs.
There are a couple of key data stores in SSE. Here are the schemas that power them.
Adding content in SSE is easy. This page shows you how.
At the heart of SSE is a file called ShowcaseInfo that is rendered via a rest endpoint. This page walks you through everything that happens along the way.
SSE is a big project. This page shows you where the most important files are for each section.
Though disabled at the moment, SSE has the capability for i18n translation / localization that isn't common in Splunk apps. Because there's little documentation out there, we're publishing our SSE docs early.