Splunk® Enterprise

Splunk Enterprise Overview

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Managing Knowledge

These tables direct you to topics for understanding and managing knowledge objects such as events, fields, lookups, and data models.

Splunk Enterprise Knowledge

Task: Look here:
Understand Splunk Enterprise knowledge What is Splunk Enterprise Knowledge?

Understand and use the Common Information Model

Manage knowledge objects Monitor and organize knowledge objects

Disable or delete knowledge objects

Events and event processing

Task: Look here:
Configure event processing Configure event processing
Manage event segmentation Manage event segmentation
Understand events and event types About event types

Define and maintain event types in Splunk Web

Fields and field extractions

Task: Look here:
Understand fields About fields

Use default fields

Configure multivalue fields

Define calculated fields

Understand and manage field extractions About fields

When Splunk Enterprise extracts fields

About Splunk Enterprise regular expressions

Build Data models

Task: Look here:
Learn about data models and objects About data models
Manage data models and objects Manage data models
Use the Data Model Editor Design data models and objects
PREVIOUS
Searching and Reporting
  NEXT
Customize and extend Splunk Enterprise

This documentation applies to the following versions of Splunk® Enterprise: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters