Did you know that all Splunk Knowledge Objects (KO) generated during a search are maintained in memory? Sure, any one KO in itself doesn’t take up a lot of memory, but run a search that returns 10 million events… You can do the math! …Learn MoreSplunk Tips & Tricks: Save some memory from those pesky extra eventtypes