knowledge

noun

A collective term for the various knowledge objects that typically are associated with the event data of a Splunk implementation (such as event types, transactions, tags, saved searches, and lookups).

Splunk knowledge gives you different ways to interpret, classify, enrich, and normalize your event data.

For more information

In the Knowledge Manager Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time