Splunk Knowledge Objects Setup

Use when the user asks to create or govern saved searches, scheduled searches, alerts, macros, lookups, eventtypes, tags, or to set knowledge-object permissions, ownership, or app sharing. Not for Enterprise Security detections, which live in splunk-enterprise-security-config. Render, validate, and apply governance for Splunk knowledge objects: saved searches and alerts, search macros, CSV and KV Store lookups (with automatic lookup binding), eventtypes, and tags, plus sharing and ownership (ACL) governance across user, app, and global scopes. This does not implement fields.conf, field extractions, FIELDALIAS, calculated fields, bulk inventory, or arbitrary ACL endpoints.

chambear2809 Updated

File contents

chambear2809/splunk-cisco-skills/tree/main/skills/splunk-knowledge-objects-setup commit 9b0f9ed30a

Frequently asked questions

npx skillmds@latest add chambear2809/splunk-knowledge-objects-setup