Intro to Knowledge Objects in Splunk


Knowledge Objects

Knowledge object

  • Types
    • field
      • field alias
      • calculated field
    • tag
      • label for data
    • macros
      • store search strings
    • data models
      • hierarchically structured data sets
      • can consist of 3 types of data sets
        • events
        • searches
        • transactions
      • can be used in pivot
    • lookup
    • report
    • event type

Knowledge Object Settings

  • recommended naming conventions:
    • use 6 keys:
      • Group
      • Type
      • Platform
      • Category
      • Time
      • Description
  • 3 ways knowledge objects can be displayed to users
    • private
    • specific app
    • all apps

Managing Knowledge Objects

  • Can be centrally managed in Settings > Knowledge > object type
  • Can filter and see actions that can be applied to objects
  • All Configurations shows all objects on the deployment
  • Admins can reassign knowledge objects to different user