<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic data model field extraction in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/data-model-field-extraction/m-p/560175#M6457</link>
    <description>&lt;P&gt;Hi,I have a dns log whose fields are not extracted properly and so I used Rex.&lt;/P&gt;&lt;P&gt;I encountered a problem. When i search index = dns * source = "516" host = dns -sender All fields are extracted correctly.&lt;/P&gt;&lt;P&gt;But when i search&lt;/P&gt;&lt;P&gt;| "from datamodel:" Network_Resolution&lt;/P&gt;&lt;P&gt;| search dns -sender&lt;/P&gt;&lt;P&gt;My fields get value of unknown.&lt;/P&gt;&lt;P&gt;Can anyone help me !!!!&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jul 2021 08:49:34 GMT</pubDate>
    <dc:creator>khanlarloo</dc:creator>
    <dc:date>2021-07-20T08:49:34Z</dc:date>
    <item>
      <title>data model field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/data-model-field-extraction/m-p/560175#M6457</link>
      <description>&lt;P&gt;Hi,I have a dns log whose fields are not extracted properly and so I used Rex.&lt;/P&gt;&lt;P&gt;I encountered a problem. When i search index = dns * source = "516" host = dns -sender All fields are extracted correctly.&lt;/P&gt;&lt;P&gt;But when i search&lt;/P&gt;&lt;P&gt;| "from datamodel:" Network_Resolution&lt;/P&gt;&lt;P&gt;| search dns -sender&lt;/P&gt;&lt;P&gt;My fields get value of unknown.&lt;/P&gt;&lt;P&gt;Can anyone help me !!!!&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 08:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/data-model-field-extraction/m-p/560175#M6457</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2021-07-20T08:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: data model field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/data-model-field-extraction/m-p/560190#M6458</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/44624"&gt;@khanlarloo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The fields extracted shall be normalized to fit into Data model that you are querying. You should have CIM app installed&amp;nbsp; to Splunk SH prior and you need to create at a highlevel eventtypes, tags and props for normalization. The process is not straight forward.&lt;/P&gt;&lt;P&gt;This link help you to achieve then if everything is successful you can query the data model (DM) however the field names would be different from you originally extracted.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.20.0/User/UsetheCIMtonormalizedataatsearchtime" target="_blank"&gt;Use the CIM to normalize data at search time - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if this reply helps and Accept the solution!&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 10:34:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/data-model-field-extraction/m-p/560190#M6458</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-20T10:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: data model field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/data-model-field-extraction/m-p/561594#M9574</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I did everything you said according to the link you sent, but there is still the same problem.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Jul 2021 12:33:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/data-model-field-extraction/m-p/561594#M9574</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2021-07-31T12:33:33Z</dc:date>
    </item>
  </channel>
</rss>

