Creating Knowledge Objects (CKO)

 

Course Content

This three-hour course is for knowledge managers who want to learn how to create knowledge objects for their search environment using the Splunk web interface. Topics will cover types of knowledge objects, the search-time operation sequence, and the processes for creating event types, workflow actions, tags, aliases, search macros, and calculated fields.

Who should attend

Knowledge Managers

Certifications

This course is part of the following Certifications:

Prerequisites

To be successful, students should have a solid understanding of the following:

  • How Splunk works
  • Knowledge objects

Course Objectives

  • Knowledge Objects and Search-time Operations
  • Creating Event Types
  • Using Event Type Builder
  • Creating Workflow Actions
  • Creating Tags and Aliases
  • Creating Search Macros

Outline: Creating Knowledge Objects (CKO)

Topic 1 – Knowledge Objects & Search-time Operations

  • Understand role of knowledge objects for enriching data
  • Define search-time operation sequence

Topic 2 – Creating Event Types

  • Define event types
  • Create event types using three methods
  • Tag event types
  • Compare event types and reports

Topic 3 – Creating Workflow Actions

  • Identify what are workflow actions
  • Create a GET, POST, and search workflow action
  • Test workflow actions

Topic 4 – Creating Tags and Aliases

  • Describe field aliases and tags
  • Create field aliases and tags
  • Search with field aliases and tags

Topic 5 – Creating Search Macros

  • Explain search macros
  • Create macros with and without arguments
  • Validate macro arguments
  • Use and preview macros at search time
  • Create and use nested macros
  • Use macros with other knowledge objects

Topic 6 – Creating Calculated Fields

  • Explain calculated fields
  • Create a calculated field
  • Use a calculated field in search

Prices & Delivery methods

Online Training

Duration
3 hours

Price
  • Online Training: CAD 635
  • Online Training: US $ 500
  • Splunk Training Units: 50 SPC
Classroom Training

Duration
3 hours

Price
  • Canada: CAD 635
  • Splunk Training Units: 50 SPC

Click on town name or "Online Training" to book Schedule

Guaranteed date:   We will carry out all guaranteed training regardless of the number of attendees, exempt from force majeure or other unexpected events, like e.g. accidents or illness of the trainer, which prevent the course from being conducted.
Instructor-led Online Training:   This computer icon in the schedule indicates that this date/time will be conducted as Instructor-Led Online Training. If you have any questions about our online courses, feel free to contact us via phone or Email anytime.

United States

Guaranteed to Run Online Training 13:00 Pacific Daylight Time (PDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Central Daylight Time (CDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Pacific Daylight Time (PDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Central Standard Time (CST) Enroll

Canada

Guaranteed to Run Online Training 13:00 Pacific Daylight Time (PDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Central Daylight Time (CDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Pacific Daylight Time (PDT) Enroll
Online Training 13:00 Eastern Daylight Time (EDT) Enroll
Guaranteed to Run Online Training 13:00 Central Standard Time (CST) Enroll