knowledge object

noun

A configuration within Splunk that is permissionable and controlled via Splunk's access control layer. Knowledge objects can be scoped to specific apps. Read/write permissions for them are granted to roles.

Splunk knowledge objects include:

For more information

In the Knowledge Manager Manual:

In the Developing Views and Apps for Splunk Web Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time