<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Model in Security</title>
    <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670190#M17461</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262677"&gt;@Mohamad_Alaa&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as I said, you have to enable datamodels and accelerations.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2023 13:34:19 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-11-29T13:34:19Z</dc:date>
    <item>
      <title>Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670112#M17450</link>
      <description>&lt;P&gt;is the output of the attached image right?&lt;BR /&gt;i can see data model per run duration but by size has no values&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 07:38:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670112#M17450</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-29T07:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670116#M17451</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262677"&gt;@Mohamad_Alaa&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you should check if the population scheduled searches are running and if they have results.&lt;/P&gt;&lt;P&gt;It seems that these scheduled searches are running, but they always have empty results.&lt;/P&gt;&lt;P&gt;Are you using CIM&amp;gt;4.X compliant add-ons?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 08:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670116#M17451</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-29T08:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670121#M17454</link>
      <description>&lt;P&gt;can you elaborate more regarding this point&amp;nbsp;&lt;BR /&gt;"you should check if the population scheduled searches are running and if they have results"&lt;BR /&gt;How i can check it?&lt;/P&gt;&lt;P&gt;i installed CIM 5.2.0 and yes i installed TA-addons but not sure about compatibility, do you recommend download to 4.x?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 08:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670121#M17454</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-29T08:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670125#M17455</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262677"&gt;@Mohamad_Alaa&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;when you choose an add-on from splunkbase, you should check the CIM compliance level.&lt;/P&gt;&lt;P&gt;about population searches, you should see in each Data Model the contrains, this is the population scheduled search&lt;/P&gt;&lt;P&gt;you should try to run these searches and see if you have results,these results are the records in the DataModel.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 09:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670125#M17455</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-29T09:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670138#M17458</link>
      <description>&lt;P&gt;when i access a data model (authentication for example)&lt;BR /&gt;I noticed the below shown error&lt;/P&gt;&lt;P&gt;"This object has no explicit index constraint. Consider adding one for better performance."&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 11:03:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670138#M17458</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-29T11:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670156#M17459</link>
      <description>&lt;P&gt;at the same time i have a message&lt;/P&gt;&lt;P&gt;The search "Network - Traffic Volume Per 30m - Model Gen" is related to the correlation search "Network - Unusual Volume of Network Activity - Rule" but it is not enabled even though the correlation search is; this will cause the correlation to fail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 11:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670156#M17459</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-29T11:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670164#M17460</link>
      <description>&lt;P&gt;I added specifically the index, still having same issue&lt;BR /&gt;I noticed the below as well&lt;/P&gt;&lt;P&gt;""App configuration&lt;BR /&gt;The "Splunk Common Information Model" app has not been fully configured yet.&lt;SPAN&gt;This app has configuration properties that can be customized for this Splunk instance. Depending on the app, these properties may or may not be required.""&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but not sure how to proceed already index was added and some data models were accelerated, i only have same button not a next or proceed button&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 12:20:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670164#M17460</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-29T12:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670190#M17461</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262677"&gt;@Mohamad_Alaa&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as I said, you have to enable datamodels and accelerations.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 13:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670190#M17461</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-29T13:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670197#M17464</link>
      <description>&lt;P&gt;problem solved, i appreciate all your responses&lt;BR /&gt;&lt;BR /&gt;once i search in SH, i should use the parameter splunk_server=* in order to see results&lt;BR /&gt;So obviously this was my issue as i should see results without such paramter&lt;BR /&gt;&lt;BR /&gt;modified the below on SH, solved it&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;C:\Program Files\Splunk\etc\system\local\distsearch.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[distributedSearch:dmc_group_indexer]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;default = false&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 14:13:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670197#M17464</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-29T14:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model</title>
      <link>https://community.splunk.com/t5/Security/Data-Model/m-p/670203#M17466</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262677"&gt;@Mohamad_Alaa&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 14:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Model/m-p/670203#M17466</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-29T14:57:36Z</dc:date>
    </item>
  </channel>
</rss>

