K
key indicator searches
Searches in Splunk Enterprise Security that create a key indicator , which you can add to a dashboard as a security metric. Key indicator searches run against the data models defined in Splunk Enterprise Security or the data models defined in the Common Information Model app. Some key indicator searches run against the count of notable events .
Related Products: Platform, Enterprise Security
key indicators
Important predefined visual security metrics defined for security domains in Splunk Enterprise Security. You can view key indicators on dashboards, where each key indicator includes a value indicator, a trend amount, a trend indicator, and a threshold value that is used to indicate the importance or priority of the indicator .
Related Products: Platform, Enterprise Security
knowledge
A collective term for the knowledge objects that typically are associated with the event data of a Splunk Enterprise implementation, such as event types , transactions , tags , saved searches , and lookups . Splunk Enterprise knowledge gives you different ways to interpret, classify, enrich, and normalize your event data.
Related Products: Platform
Related Terms: knowledge bundle, knowledge manager
knowledge bundle
The set of knowledge objects that a search head distributes to its search peers so that they can process a distributed search .
Related Products: Platform
Related Terms: search management
knowledge manager
A person who provides centralized oversight and maintenance of knowledge objects for a Splunk Enterprise implementation. Knowledge managers:
Related Products: Platform
knowledge object
A user-defined entity that enriches the existing data in the Splunk platform. You can use knowledge objects to get specific information about your data. When you create a knowledge object, you can keep it private or you can share it with other users. Knowledge managers manage how their organizations use knowledge objects in their Splunk Enterprise deployments . Splunk Enterprise knowledge objects include saved searches , event types , tags , field extractions , lookups , reports , alerts , data models , workflow actions , and fields .
Related Products: Platform
KV store
See App Key Value Store .
Related Products: Platform
KV store captain
The KV store captain is the single instance in the app key value store that receives write operations. Other KV store instances replicate data from the captain. In a search head cluster, when a node receives a write request, the KV store delegates the write to the KV store captain, while the KV store keeps read requests local.
Related Products: Platform