What's in this manual?
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
What's in this manual?
We've designed the Knowledge Manager manual to show you how to best use and extend Splunk so that it works with your data in a manner that fulfills the needs of your enterprise.
You'll want to consult this manual as you optimize, maintain, and expand your Splunk deployment over time.
There's a lot of important conceptual information in here, as well a number of step-by-step procedures, all designed to help you make your Splunk deployment the best it can be. You'll learn:
- How indexing works in Splunk.
- How to manage and maintain Splunk "knowledge objects" such as events, event types, fields, source types, tags, and transactions.
- Best practices for working with fields.
- Strategies for grouping conceptually related events into transactions.
Read on for more about this new manual and who it's for.
Make a PDF
If you'd like a PDF of any version of this manual, click the pdf version link above the table of contents bar on the left side of this page. A PDF version of the manual is generated on the fly for you, and you can save it or print it out to read later.
This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.