Splunk® Enterprise

Splunk Enterprise Overview

Acrobat logo Download manual as PDF


Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Managing Knowledge

These tables direct you to topics for understanding and managing knowledge objects such as events, fields, lookups, and data models.

Splunk Enterprise Knowledge

Task: Look here:
Understand Splunk Enterprise knowledge What is Splunk Enterprise Knowledge?

Understand and use the Common Information Model

Manage knowledge objects Monitor and organize knowledge objects

Disable or delete knowledge objects

Events and event processing

Task: Look here:
Configure event processing Configure event processing
Manage event segmentation Manage event segmentation
Understand events and event types About event types

Define and maintain event types in Splunk Web

Fields and field extractions

Task: Look here:
Understand fields About fields

Use default fields

Configure multivalue fields

Define calculated fields

Understand and manage field extractions About fields

When Splunk Enterprise extracts fields

About Splunk Enterprise regular expressions

Build Data models

Task: Look here:
Learn about data models and objects About data models
Manage data models and objects Manage data models
Use the Data Model Editor Design data models and objects
Last modified on 17 July, 2018
PREVIOUS
Searching and Reporting
  NEXT
Customize and extend Splunk Enterprise

This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters