Skip to main content
Warning
This app is archived. App archiving documentation
Knowledge Object Explorer app icon

Knowledge Object Explorer

The Knowledge Object Explorer helps you understand how Splunk turns a search and your configured knowledge objects into a normalized search.Built by Martin Müller
splunk product badge

Default Version 1.3.0

January 8, 2020

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

Rating
5
(4)

Log in to rate this app

Support
Archived App

The Knowledge Object Explorer helps you understand how Splunk turns a search and your configured knowledge objects into a normalized search. You get a tree visualization for the tags, eventtypes, reverse lookups, fields, field aliases, calculated fields, and plain strings that appear in your search after expansion. For a quick dive into your environment, the Browse page parses all Tags, Event Types, and Data Model Objects for their normalizedSearch length letting you explore and optimize the worst offenders first. This is the companion app to my .conf 2015 talk "Optimizing Splunk Knowledge Objects", the session includes lots of search expansion background information and some demos of the Knowledge Object Explorer. A note on Splunk Enterprise 6.6: While the Knowledge Object Explorer does work with 6.6, it does not mirror the litsearch optimization attempts built into 6.6.