Creating Knowledge Objects

Information

Tato část není lokalizována

This three-hour course is for knowledge managers who want to learn how to create knowledge objects for their search environment using the Splunk web interface. Topics will cover types of knowledge objects, the search-time operation sequence, and the processes for creating event types, workflow actions, tags, aliases, search macros,
and calculated fields.

Course structure

Knowledge Objects & Search-time Operations

  • Understand role of knowledge objects for enriching data
  • Define search-time operation sequence

Creating Event Types

  • Define event types
  • Create event types using three methods
  • Tag event types
  • Compare event types and reports

Creating Workflow Actions

  • Identify what are workflow actions
  • Create a GET, POST, and search workflow action
  • Test workflow actions

Creating Tags and Aliases

  • Describe field aliases and tags
  • Create field aliases and tags
  • Search with field aliases and tags

Creating Search Macros

  • Explain search macros
  • Create macros with and without arguments
  • Validate macro arguments
  • Use and preview macros at search time
  • Create and use nested macros
  • Use macros with other knowledge objects

Creating Calculated Fields

  • Explain calculated fields
  • Create a calculated field
  • Use a calculated field in search

Více o kurzu

Creating Knowledge Objects

Selected course term

 ONLINE

Price
13 700 CZK + 21% VAT

Contact the supplier


Because of spam protection, please answer the following question how much is four and four ? Write the sum in digits.