Splunk is a highly versatile software platform renowned for processing and visualizing sizeable real-time data quantities. To unlock its full potential and tailor it to your specific needs, you may install Splunk add-ons, modules designed to augment Splunk’s capabilities with additional features and functionalities. Do note that special permissions are required to install add-ons. Furthermore, each add-on has its own distinct installation and configuration procedures. Reading the add-on’s documentation is advisable to comprehend its usage and configuration.
Method 1: Using the ‘Find More Apps’ Feature to Install Splunk Add-Ons
This method requires an internet connection on the Splunk Server. To install a Splunk add-on through the Splunk Web interface, please follow the steps provided below:
1. Access your Splunk instance. Start your Splunk server and then access Splunk Web on your web browser. You will be required to log in using your user credentials. Usually, it’s at
if you’re on the same machine as your Splunk server.
2. Locate the [Apps] button in the interface’s upper left corner. Proceed by selecting [Find More Apps]. This action will redirect you to Splunkbase, the marketplace for all Splunk apps and add-ons.
3. Utilize the search function to find the specific add-on you desire. When located, click the [Install] button associated with the add-on.
4. Subsequently, you will be requested to provide your Splunk.com credentials. Please enter the necessary information and proceed by clicking “Login and Install.”
5. A prompt will appear, asking for your consent to restart Splunk. Please choose “Restart Now” to proceed. If not, note that you can choose to “restart” later. However, the installed add-on will only be available for use after the restart has taken place.
Method 2: Install Splunk Add-On from the Splunkbase site
This method doesn’t require an internet connection on the Splunk server. You will need to download the file on an external computer that does and transfer the file to the Splunk server for installation.
How to download the add-on on a computer with an internet connection
1. Open a web browser and navigate to Splunkbase at
2. Once on the site, use the search bar at the top to search for the specific add-on you want. You can also browse through the available add-ons by category if you prefer.
3. Click on the add-on’s name in the search results to go to its specific page. This page contains details about the add-on, including its description, version information, and any specific installation instructions or requirements.
4. Look for the “Download” button on the page’s right side. Click this button to download the add-on. You can install the add-on directly into your Splunk Enterprise instance by downloading the .spl or .tgz file and installing it. Please make sure to take note of where the file is being saved on your local machine to access it easily in the future.
5. Sometimes, you may be required to log into your Splunk account before downloading the add-on. If prompted, enter your credentials to continue with the download.
6. Move the downloaded file from the computer to the Splunk server. Mind where you put the file on the server.
How to install Splunk add-on on Splunk server without an internet connection
1. Access Splunk Enterprise: Next, you must sign in to your Splunk instance using your login details through the web interface.
2. Click the “Apps” menu on the home page’s upper left side, then select “Manage Apps.”
3. select “Install the app from file ” once on the apps page.”
4. A dialog box titled “Upload app” will pop up. Here, you must click “Choose File.”
5. Navigate to the location of the .spl or .tgz file you downloaded earlier and select it.
6. Click “Upload” to install the Splunk add-on.
7. You might need to restart your Splunk instance for the add-on to work correctly.
8. After installing your add-on, you may need to perform additional setup depending on your chosen add-on. You can find detailed instructions for this in the specific documentation of the add-on.
9. You can check if the Splunk add-on was installed correctly by returning to the “Manage Apps” page. The add-on should be there.
Method 3: Install Splunk add-on manually
This approach also doesn’t necessitate online access for the Splunk server. Instead, you’ll have to download the requisite file using a separate computer with internet capabilities and then move this file to the Splunk server to proceed with the installation.
For example, we will use the Splunk add-on “Python for Scientific Computing (for Windows 64-bit)”. This method is relevant mainly to the users that would get an error message:
failed to extract the app from C:\Program Files\Splunk\var\run\1q2aw1qa2w1q2.tar.gz to C:\Program Files\Splunk\var\run\splunk\bundle_tmp\868s7d6f8s7d6f8s7d6f: The system cannot find the path specified.
Such an issue arises primarily with larger files, like this add-on, which has a size of around 450MB.
Follow the steps in “How to download Splunk add-on on the computer with an internet connection” from the previous method to download the add-on file. Then continue executing the steps in this method:
1. Download the “Python for Scientific Computing (for Windows 64-bit)” add-on.
2. Once the download completes, transfer this file to your Windows computer that hosts the Splunk Enterprise server.
3. Unarchive the downloaded archive using a tool like WinRar. Right-click the archived file and choose “Extract Here.”
4. Locate the Extracted Folder. Post extraction, identify the resultant folder:
5. Navigate to the “apps” directory of your Splunk installation, typically located at:
6: Move the extracted folder into the apps directory, resulting in the following path:
7. To apply the changes, you need to restart Splunk.
8. After restarting, log in to the Splunk web console.
9. choose [Apps] and then [Manage Apps] from the top menu.
10. Finally, check that the “Python for Scientific Computing” add-on is in the installed apps list and visible in the [Apps] menu. Successful visibility confirms a successful installation. If the add-on is absent, try repeating the process or contact Splunk support for further assistance.