Creating Knowledge Objects
Upcoming Classes
Online
Instructor-led online training
Location | Mar 2023 | Apr 2023 | May 2023 | Jun 2023 | Jul 2023 | Aug 2023 | Sep 2023 |
---|---|---|---|---|---|---|---|
AMER Eastern Time - Virtual |
Apr 10 Apr 20 |
May 18 |
Jun 14 | ||||
APAC Singapore - Virtual |
Apr 13 |
May 29 |
Jul 10 |
Aug 24 | |||
AMER Pacific Time - Virtual |
Apr 13 | ||||||
APAC Sydney - Virtual |
Apr 17 |
May 25 | |||||
EMEA UK Time - Virtual |
Apr 27 |
Jun 12 |
Jul 12 |
Sep 4 |
|||
AMER Brazil Time - Virtual (Portuguese) |
May 10 May 24 |
Jul 5 |
Aug 10 Aug 30 |
Sep 6 |
|||
EMEA Greenwhich Mean Time - Virtual |
May 11 | ||||||
AMER Eastern Time - Virtual (Spanish) |
May 17 | ||||||
Fast Lane Italia - Milano |
Jul 11 |

Summary
This three-hour course is for knowledge managers who want to learn how to create knowledge objects for their search environment using the Splunk web interface. Topics will cover types of knowledge objects, the search-time operation sequence, and the processes for creating event types, workflow actions, tags, aliases, search macros, and calculated fields.
Description
- Knowledge Objects and Search-time Operations
- Creating Event Types
- Using Event Type Builder
- Creating Workflow Actions
- Creating Tags and Aliases
- Creating Serach Macros
Objectives
Topic 1 – Knowledge Objects & Search-time Operations
- Understand role of knowledge objects for enriching data
- Define search-time operation sequence
Topic 2 – Creating Event Types
- Define event types
- Create event types using three methods
- Tag event types
- Compare event types and reports
Topic 3 – Creating Workflow Actions
- Identify what are workflow actions
- Create a GET, POST, and search workflow action
- Test workflow actions
Topic 4 – Creating Tags and Aliases
- Describe field aliases and tags
- Create field aliases and tags
- Search with field aliases and tags
Topic 5 – Creating Search Macros
- Explain search macros
- Create macros with and without arguments
- Validate macro arguments
- Use and preview macros at search time
- Create and use nested macros
- Use macros with other knowledge objects
Topic 6 – Creating Calculated Fields
- Explain calculated fields
- Create a calculated field
- Use a calculated field in search