Ch. 8 Intro to Knowledge Objects
Knowledge Objects is basically the name for all the tools within in Splunk ex. Fields, Reports, Alerts, etc
Macro - allow you to save a full or sub search query as a custom shortcut, which can be included in other searches. Its like creating a functions
Workflow
Naming actions
Power Users and Admins can create and share KxObj for all users, as well as modify
Admin is the only role that is allowed to grant access to KxObj to all Apps, they can also edit private obj created by any role
Calculated Fields & Macros can contain eval expressions
Workflow Actions - knowledge object type can communicate with external sources using the HTTP GET and POST method
Reports and Alerts can be used to scheduled to execute at specific times?
Regular expressions and Delimitiers can be used to manually extract fields
Fields Sidebar - where all fields retrived by Splunk can be viewed from a earch result of an index
Data models can be searched in Pivot