K

key indicator searches

Searches in Splunk Enterprise Security that create a key indicator , which you can add to a dashboard as a security metric. Key indicator searches run against the data models defined in Splunk Enterprise Security or the data models defined in the Common Information Model app. Some key indicator searches run against the count of notable events .

Related Products: Platform, Enterprise Security

key indicators

Important predefined visual security metrics defined for security domains in Splunk Enterprise Security. You can view key indicators on dashboards, where each key indicator includes a value indicator, a trend amount, a trend indicator, and a threshold value that is used to indicate the importance or priority of the indicator .

Related Products: Platform, Enterprise Security

knowledge

A collective term for the knowledge objects that typically are associated with the event data of a Splunk Enterprise implementation, such as event types , transactions , tags , saved searches , and lookups . Splunk Enterprise knowledge gives you different ways to interpret, classify, enrich, and normalize your event data.

Related Products: Platform

Related Terms: knowledge bundle, knowledge manager

knowledge bundle

The set of knowledge objects that a search head distributes to its search peers so that they can process a distributed search .

Related Products: Platform

Related Terms: search management

knowledge manager

A person who provides centralized oversight and maintenance of knowledge objects for a Splunk Enterprise implementation. Knowledge managers:

Related Products: Platform

knowledge object

A user-defined entity that enriches the existing data in the Splunk platform. You can use knowledge objects to get specific information about your data. When you create a knowledge object, you can keep it private or you can share it with other users. Knowledge managers manage how their organizations use knowledge objects in their Splunk Enterprise deployments . Splunk Enterprise knowledge objects include saved searches , event types , tags , field extractions , lookups , reports , alerts , data models , workflow actions , and fields .

Related Products: Platform

KV store

See App Key Value Store .

Related Products: Platform

KV store captain

The KV store captain is the single instance in the app key value store that receives write operations. Other KV store instances replicate data from the captain. In a search head cluster, when a node receives a write request, the KV store delegates the write to the KV store captain, while the KV store keeps read requests local.

Related Products: Platform