Creating Knowledge Objects (CKO)

 

Course Content

This three-hour course is for knowledge managers who want to learn how to create knowledge objects for their search environment using the Splunk web interface. Topics will cover types of knowledge objects, the search-time operation sequence, and the processes for creating event types, workflow actions, tags, aliases, search macros, and calculated fields.

Who should attend

Knowledge Managers

Certifications

This course is part of the following Certifications:

Prerequisites

To be successful, students should have a solid understanding of the following:

  • How Splunk works
  • Knowledge objects

Course Objectives

  • Knowledge Objects and Search-time Operations
  • Creating Event Types
  • Using Event Type Builder
  • Creating Workflow Actions
  • Creating Tags and Aliases
  • Creating Search Macros

Outline: Creating Knowledge Objects (CKO)

Module 1 – Knowledge Objects & Search-time Operations

  • Understand role of knowledge objects for enriching data
  • Define search-time operation sequence

Module 2 – Create Event Types

  • Define event types
  • Create event types using three methods
  • Use event types
  • Find event types
  • Tag event types
  • Compare event types and reports

Module 3 – Create Workflow Actions

  • Administer Splunk user roles
  • Integrate Splunk with LDAP, Active Directory, or SAML

Module 4 – Create Tags and Aliases

  • Describe field aliases
  • Create field aliases
  • Search with field aliases
  • Define tags
  • Create and view tags
  • Search with tags
  • Manage tags

Module 5 – Create Search Macros

  • Define macros
  • Create macros with and without arguments
  • Validate macro arguments
  • Use and preview macros at search time
  • Use nested macros
  • Use macros with other knowledge objects
  • Use tags/event types with macros
  • Create macros: considerations

Module 6 – Create Calculated Fields

  • Explain calculated fields
  • Create a calculated field
  • Use a calculated field

Prices & Delivery methods

Online Training

Duration
3 hours

Price
  • US $ 500
  • Splunk Training Units: 50 SPC
Classroom Training

Duration
3 hours

Price
  • United States: US $ 500
  • Splunk Training Units: 50 SPC

Click on town name or "Online Training" to book Schedule

Guaranteed date:   This green checkmark in the Upcoming Schedule below indicates that this session is Guaranteed to Run.
Instructor-led Online Training:   This is an Instructor-Led Online (ILO) course. These sessions are conducted via WebEx in a VoIP environment and require an Internet Connection and headset with microphone connected to your computer or laptop. If you have any questions about our online courses, feel free to contact us via phone or Email anytime.

United States

Guaranteed to Run Online Training 13:00 Pacific Daylight Time (PDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Central Daylight Time (CDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Pacific Daylight Time (PDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Central Standard Time (CST) Enroll

Canada

Guaranteed to Run Online Training 13:00 Pacific Daylight Time (PDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Central Daylight Time (CDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Pacific Daylight Time (PDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Central Standard Time (CST) Enroll