<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting new index data into data model in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Getting-new-index-data-into-data-model/m-p/562785#M100286</link>
    <description>&lt;P&gt;This is helpful thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 10 Aug 2021 17:47:25 GMT</pubDate>
    <dc:creator>ygoltsev</dc:creator>
    <dc:date>2021-08-10T17:47:25Z</dc:date>
    <item>
      <title>Getting new index data into data model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-new-index-data-into-data-model/m-p/562769#M100283</link>
      <description>&lt;P&gt;Hi - I am trying to configure the authentication data model to include additional source data indexes.&lt;/P&gt;&lt;P&gt;We want to include Duo logs in our dashboard in Splunk ES, but am unsure how to get the data model to recognize the new data.&amp;nbsp; The logs also appear to be in a different format, but I notice there's a method to "eval" the fields in the data model.&amp;nbsp; Can you please advise best practice for this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 16:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-new-index-data-into-data-model/m-p/562769#M100283</guid>
      <dc:creator>ygoltsev</dc:creator>
      <dc:date>2021-08-10T16:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Getting new index data into data model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-new-index-data-into-data-model/m-p/562780#M100285</link>
      <description>&lt;P&gt;The first step is to make sure the Duo logs are CIM-compliant.&amp;nbsp; Check the manual at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.20.0/User/Authentication" target="_blank"&gt;https://docs.splunk.com/Documentation/CIM/4.20.0/User/Authentication&lt;/A&gt;&amp;nbsp;to see what fields the DM expects.&amp;nbsp; Add FIELDALIAS and other settings to props.conf to create those fields.&amp;nbsp; It's not necessary to have all of them, but you'll want to have the fields your ES use cases need.&lt;/P&gt;&lt;P&gt;Once that's done, go to ES's Settings menu and select "CIM Setup".&amp;nbsp; Add the Duo index to the list of indexes used by the Authentication datamodel and click Save.&amp;nbsp; Wait for the DM to rebuild and check the results.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 17:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-new-index-data-into-data-model/m-p/562780#M100285</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-08-10T17:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Getting new index data into data model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-new-index-data-into-data-model/m-p/562785#M100286</link>
      <description>&lt;P&gt;This is helpful thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 17:47:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-new-index-data-into-data-model/m-p/562785#M100286</guid>
      <dc:creator>ygoltsev</dc:creator>
      <dc:date>2021-08-10T17:47:25Z</dc:date>
    </item>
  </channel>
</rss>

