Deployment Architecture

How to compare knowledge objects on two search heads?


What’s the best way to write a query to list all knowledge objects on a search head, and then compare it to the knowledge objects on another search head?

0 Karma


So far I’ve ended up using the REST endpoint of services/directory to grab most of what I need.

0 Karma

Super Champion

Splunk does not store knowledge objects in any index. Knowledge objects are contained in .conf files and .xml files that are stored in the directory hierarchy under $SPLUNK_HOME/etc

Shameless promotion: there is an app on Splunkbase called X-ray Splunk which collects information about the knowledge objects and presents it in a variety of dashboards. It doesn't seem to work yet on all OSes, but it is free.
Have a look at this ans.

Let me know if this helps!

*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>