The Knowledge Object Explorer helps you understand how Splunk turns a search and your configured knowledge objects into a normalized search.
You get a tree visualization for the tags, eventtypes, reverse lookups, fields, field aliases, calculated fields, and plain strings that appear in your search after expansion. For a quick dive into your environment, the Browse page parses all Tags, Event Types, and Data Model Objects for their normalizedSearch length letting you explore and optimize the worst offenders first.
This is the companion app to my .conf 2015 talk "Optimizing Splunk Knowledge Objects", the session includes lots of search expansion background information and some demos of the Knowledge Object Explorer.
A note on Splunk Enterprise 6.6: While the Knowledge Object Explorer does work with 6.6, it does not mirror the litsearch optimization attempts built into 6.6.
Resources
Log in to report this app listing