| agent_management | Configure the Agent Management feature | N/A | reference/conf/agent_management.md |
| alert_actions | Configure alert actions (email, script, webhook) | Search | reference/conf/alert_actions.md |
| app | App metadata (label, version, author, visibility) | N/A | reference/conf/app.md |
| audit | Configure auditing and event hashing | N/A | reference/conf/audit.md |
| authentication | Toggle between Splunk built-in auth, LDAP, or SAML | N/A | reference/conf/authentication.md |
| authorize | Configure roles and granular access controls | N/A | reference/conf/authorize.md |
| bookmarks | Bookmark monitoring console URLs | N/A | reference/conf/bookmarks.md |
| checklist | Customize monitoring console health checks | N/A | reference/conf/checklist.md |
| collections | Configure KV Store collections | Search | reference/conf/collections.md |
| commands | Register custom search commands | Search | reference/conf/commands.md |
| datamodels | Configure data model acceleration and attributes | Search | reference/conf/datamodels.md |
| default-meta | Set permissions for objects in a Splunk app | N/A | reference/conf/default-meta.md |
| deploymentclient | Configure deployment client behavior | N/A | reference/conf/deploymentclient.md |
| distsearch | Configure distributed search | Search | reference/conf/distsearch.md |
| event_renderers | Configure event rendering properties | N/A | reference/conf/event_renderers.md |
| eventtypes | Define event type classifications | Search | reference/conf/eventtypes.md |
| federated | Search data outside your Splunk deployment | Search | reference/conf/federated.md |
| fields | Create multivalue fields, add indexed field search capability | Search | reference/conf/fields.md |
| global-banner | Display a global banner on all Splunk Web pages | N/A | reference/conf/global-banner.md |
| health | Set thresholds for proactive component monitoring | N/A | reference/conf/health.md |
| indexes | Manage index settings (paths, sizes, retention, SmartStore) | Indexing | reference/conf/indexes.md |
| inputs | Configure data inputs (monitor, TCP, UDP, scripted, HTTP) | Input | reference/conf/inputs.md |
| instance-cfg | Instance identification and management | N/A | reference/conf/instance-cfg.md |
| limits | Set search and system limits (result sizes, concurrency) | Search | reference/conf/limits.md |
| literals | Customize Splunk Web text strings | N/A | reference/conf/literals.md |
| macros | Define search macros | Search | reference/conf/macros.md |
| messages | Customize Splunk Web messages | N/A | reference/conf/messages.md |
| metric_rollups | Configure metric rollup policies | Indexing | reference/conf/metric_rollups.md |
| multikv | Configure extraction for table-like events (ps, netstat) | Search | reference/conf/multikv.md |
| outputs | Configure forwarding behavior (TCP, syslog, HTTP) | Output | reference/conf/outputs.md |
| passwords | Maintain app credential information | N/A | reference/conf/passwords.md |
| procmon-filters | Monitor Windows process data | Input | reference/conf/procmon-filters.md |
| props | Indexing/search properties: timestamp, line breaking, field extraction, source type rules | Input/Parsing/Search | reference/conf/props.md |
| pubsub | Define custom deployment server clients | N/A | reference/conf/pubsub.md |
| restmap | Create custom REST endpoints | N/A | reference/conf/restmap.md |
| rolling_upgrade | Configure automated rolling upgrades | N/A | reference/conf/rolling_upgrade.md |
| savedsearches | Define reports, scheduled searches, and alerts | Search | reference/conf/savedsearches.md |
| searchbnf | Configure search assistant syntax definitions | Search | reference/conf/searchbnf.md |
| segmenters | Configure event segmentation | Indexing/Search | reference/conf/segmenters.md |
| server | System configuration: SSL, clustering, KV store, license | N/A | reference/conf/server.md |
| serverclass | Define deployment server classes | N/A | reference/conf/serverclass.md |
| serverclass-seed | Configure deployment client app seeding at startup | N/A | reference/conf/serverclass-seed.md |
| source-classifier | Terms to ignore when classifying source types | Parsing | reference/conf/source-classifier.md |
| sourcetypes | Machine-generated source type learning rules | Parsing | reference/conf/sourcetypes.md |
| tags | Configure tags for fields and event types | Search | reference/conf/tags.md |
| telemetry | Configure telemetry data collection | N/A | reference/conf/telemetry.md |
| times | Define custom time ranges for the time picker | Search | reference/conf/times.md |
| transactiontypes | Define transaction types for transaction search | Search | reference/conf/transactiontypes.md |
| transforms | Regex transforms, lookup definitions, routing rules | Parsing/Search | reference/conf/transforms.md |
| ui-prefs | Configure UI preferences per view | N/A | reference/conf/ui-prefs.md |
| user-prefs | Per-user Splunk Web preferences | N/A | reference/conf/user-prefs.md |
| user-seed | Set default user and password | N/A | reference/conf/user-seed.md |
| viewstates | Configure UI view states (chart settings) | N/A | reference/conf/viewstates.md |
| visualizations | Register app visualizations with the system | N/A | reference/conf/visualizations.md |
| web | Configure Splunk Web (HTTP, HTTPS, certificates) | N/A | reference/conf/web.md |
| web-features | Configure Splunk Web feature flags | N/A | reference/conf/web-features.md |
| wmi | Configure WMI inputs (Windows only) | Input | reference/conf/wmi.md |
| workflow_actions | Configure workflow actions in event viewers | N/A | reference/conf/workflow_actions.md |
| workload_policy | Enable/disable workload management admission rules | N/A | reference/conf/workload_policy.md |
| workload_pools | Configure workload pools (resource groups) | N/A | reference/conf/workload_pools.md |
| workload_rules | Configure workload rules for pool access and priority | N/A | reference/conf/workload_rules.md |