splunk-knowledge-objects

Govern Splunk knowledge objects across apps with local.meta overlays.

36|7|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-knowledge-objects
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: splunk-knowledge-objects
Source: https://github.com/chambear2809/splunk-cisco-skills/tree/main/skills/splunk-knowledge-objects
Command: npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-knowledge-objects

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

Governance of Splunk knowledge objects across apps, ensuring consistent sharing, ownership, and metadata, while supporting auditing and remediation workflows.

Core Features & Use Cases

  • Govern saved searches, macros, lookups, eventtypes, and tags across apps
  • Stage governance metadata into local.meta and governance templates for safe deployment
  • Detect and remediate orphaned or private objects, and reassign ownership

Quick Start

Render governance assets for your Splunk apps and review outputs before applying changes.

Frequently Asked Questions about splunk-knowledge-objects

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I govern Splunk knowledge objects across multiple apps?

You can enforce Splunk knowledge object governance by rendering governance assets and staging local.meta overlays to enforce consistent sharing, ownership, and metadata for saved searches, macros, and lookups.

What is the best way to remediate orphaned Splunk saved searches and reports?

Remediating orphaned Splunk saved searches and reports involves detecting private objects across apps and performing safe ownership reassignments using staged conf templates to avoid editing shipped default configurations.

How do I audit metadata ownership for Splunk macros, eventtypes, and tags?

Auditing Splunk macros, eventtypes, and tags metadata ownership requires rendering governance assets that map current sharing permissions and ownership states across your deployed apps.

Can I safely reassign ownership of Splunk lookups without modifying default configurations?

Yes, you can safely reassign ownership of Splunk lookups by applying local.meta overlays and staged conf templates, which include safeguards to prevent editing shipped default configurations.

Does this approach support governance for Splunk field extractions and alerts?

Yes, Splunk governance supports field extractions and alerts alongside saved searches, reports, macros, lookups, eventtypes, and tags by rendering consistent metadata templates for safe deployment.