Knowledge Management

Exporting knowledge objects from Splunk_TA_nix?

daniel333
Builder

All,

I just installed Splunk_TA_nix and noticed that it's tags are quite expensive. I'd like to limit the knowledge object to searching and reporting and "MyCustomApp". How would I copy and modify default.meta in that situation?

 vi default.meta
# Application-level permissions
[]
access = read : [ * ], write : [ admin ]
export = system

[savedsearches]
owner = admin

## Exclude export of custom alert actions
[alert_actions/email]
export = none
0 Karma

hettervik
Builder

I don't know if it's possible to export knowledge objects to certain apps. As far as I know is either "global" or nothing. However, if you haven't done so already, you should try to edit tags.conf and possibly eventtypes.conf to optimize the tagging. Make sure that the searches only search in relevant indexes, at least.

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...