The remaining topics in this chapter, along with fields, are collectively called knowledge objects, which are the user-defined entities that enrich the existing data in Splunk. I will provide a brief description and example of some of the most common knowledge objects in this chapter; you can learn more about all of the knowledge objects in the Knowledge Manager Manual: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/WhatisSplunkknowledge.
Other knowledge objects
Event types – tags – aliases
Splunk event types, tags, and aliases are used together or separately to associate search criteria and various field values to a common name. This can simplify search strings and allow for one-location modification...