Ch. 8 Intro to Knowledge Objects

  • Knowledge Objects is basically the name for all the tools within in Splunk ex. Fields, Reports, Alerts, etc

    • Macro - allow you to save a full or sub search query as a custom shortcut, which can be included in other searches. Its like creating a functions

    • Workflow

  • Naming actions

  • Power Users and Admins can create and share KxObj for all users, as well as modify

  • Admin is the only role that is allowed to grant access to KxObj to all Apps, they can also edit private obj created by any role

  • Calculated Fields & Macros can contain eval expressions

  • Workflow Actions - knowledge object type can communicate with external sources using the HTTP GET and POST method

  • Reports and Alerts can be used to scheduled to execute at specific times?

  • Regular expressions and Delimitiers can be used to manually extract fields

  • Fields Sidebar - where all fields retrived by Splunk can be viewed from a earch result of an index

  • Data models can be searched in Pivot