<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data model tags whitelist in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/582882#M102702</link>
    <description>&lt;P&gt;I did a test, trying to figured out what's going on.&lt;/P&gt;&lt;P&gt;This is the situation with default tags whitelist:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_0-1643359560543.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17736iFC0F29B1CFD146BA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_0-1643359560543.png" alt="tbonfa_0-1643359560543.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_1-1643359571746.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17737i4BB8581BF3920B0B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_1-1643359571746.png" alt="tbonfa_1-1643359571746.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then I added the tag authentication as whitelist tag and performed the same search in the same discrete timeframe:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_2-1643359616288.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17738i8C34046CC93A8561/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_2-1643359616288.png" alt="tbonfa_2-1643359616288.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_3-1643359622397.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17739i5709D4ADE140A80A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_3-1643359622397.png" alt="tbonfa_3-1643359622397.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It seems that when i put a specific tag inside the whitelist box, then I can search and filter on it in the search (if exists obviously). The events did'nt change, the count is the same.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;are you sure about docs' mistake?&lt;/P&gt;&lt;P&gt;(Sorry for italian screenshots)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jan 2022 08:51:33 GMT</pubDate>
    <dc:creator>tbonfa</dc:creator>
    <dc:date>2022-01-28T08:51:33Z</dc:date>
    <item>
      <title>Data model tags whitelist- Should I add tags used inside constraints on my own?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/582821#M102697</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I installed the Splunk CIM on my Splunk instance and I've a doubt regarding tags whitelisting.&lt;/P&gt;
&lt;P&gt;The docs says that (&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Knowledge/Designdatamodelobjects" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.4/Knowledge/Designdatamodelobjects&lt;/A&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_0-1643310375464.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17722iE276A93C658D8388/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_0-1643310375464.png" alt="tbonfa_0-1643310375464.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This means that the tags whitelist configuration in Splunk CIM settings must have at least tags used within the constraints used in the specific datamodel.&lt;/P&gt;
&lt;P&gt;Let's do an example with Authentication datamodel.&lt;/P&gt;
&lt;P&gt;This is the default tags whitelist configuration after installing the app:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_1-1643310525523.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17723iB3DC047C00C5305E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_1-1643310525523.png" alt="tbonfa_1-1643310525523.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And this is the root dataset constraint:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_2-1643310575927.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17724i01C7BDFC20F92A9A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_2-1643310575927.png" alt="tbonfa_2-1643310575927.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;How you can see, the tag authentication used as root constraint isn't by default one of whitelisted tags for Authentication datamodel.&lt;/P&gt;
&lt;P&gt;Shall I add tags used inside constraints on my own? Or is there something I'm missing?&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 15:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/582821#M102697</guid>
      <dc:creator>tbonfa</dc:creator>
      <dc:date>2022-09-14T15:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Data model tags whitelist</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/582829#M102698</link>
      <description>&lt;P&gt;I've used the Authentication datamodel without modification many times so I suspect the documentation is incorrect.&amp;nbsp; Please submit feedback on it.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 20:38:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/582829#M102698</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-01-27T20:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Data model tags whitelist</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/582882#M102702</link>
      <description>&lt;P&gt;I did a test, trying to figured out what's going on.&lt;/P&gt;&lt;P&gt;This is the situation with default tags whitelist:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_0-1643359560543.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17736iFC0F29B1CFD146BA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_0-1643359560543.png" alt="tbonfa_0-1643359560543.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_1-1643359571746.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17737i4BB8581BF3920B0B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_1-1643359571746.png" alt="tbonfa_1-1643359571746.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then I added the tag authentication as whitelist tag and performed the same search in the same discrete timeframe:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_2-1643359616288.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17738i8C34046CC93A8561/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_2-1643359616288.png" alt="tbonfa_2-1643359616288.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbonfa_3-1643359622397.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17739i5709D4ADE140A80A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tbonfa_3-1643359622397.png" alt="tbonfa_3-1643359622397.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It seems that when i put a specific tag inside the whitelist box, then I can search and filter on it in the search (if exists obviously). The events did'nt change, the count is the same.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;are you sure about docs' mistake?&lt;/P&gt;&lt;P&gt;(Sorry for italian screenshots)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 08:51:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/582882#M102702</guid>
      <dc:creator>tbonfa</dc:creator>
      <dc:date>2022-01-28T08:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Data model tags whitelist</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/582923#M102713</link>
      <description>&lt;P&gt;Perhaps more imprecise than wrong.&amp;nbsp; Saying the datamodel MUST contain all of the tags specified in the constraint implies the DM will not function without it.&amp;nbsp; Your test shows the DM does function, at least partially.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 13:02:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/582923#M102713</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-01-28T13:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Data model tags whitelist</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/613108#M106090</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just here to add some information about your issue.&lt;/P&gt;&lt;P&gt;I don't think this is a error in the documentation but it's just tricky &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Indeed it is mentioned : "&lt;EM&gt;The list must include all of the tags in the constraint searches for the data model and any additional tags that you commonly use in searches that reference the data model.&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;The important words here are : &lt;EM&gt;"&lt;STRONG&gt;in the constraint searches for the data model&lt;/STRONG&gt;", &lt;/EM&gt;I don't know if you noticed but a datamodel have two properties : Events and Searches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your example you show the data model "event" and not the searches. If I take another datamodel like "Malware" we can see that here we have a searches which uses tags (malware and operation) !&lt;/P&gt;&lt;P&gt;I think the documentation wants to say that if you want to use &lt;U&gt;&lt;STRONG&gt;SEARCHES&lt;/STRONG&gt; &lt;/U&gt;of a datamodel then you need to add the tags in the whitelist. (hope this is understandable)&lt;/P&gt;&lt;P&gt;Here is a screenshot that illustrate this example.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="XavG_KS_1-1663169558311.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21471i900CE065944D7B44/image-size/medium?v=v2&amp;amp;px=400" role="button" title="XavG_KS_1-1663169558311.png" alt="XavG_KS_1-1663169558311.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In this example, if you don't had the "operation" tag in the &lt;EM&gt;whitelist_tag&lt;/EM&gt; then the &lt;U&gt;&lt;STRONG&gt;search&lt;/STRONG&gt; &lt;/U&gt;will not work.&lt;/P&gt;&lt;P&gt;Hope this is helpful, have a nice day&lt;/P&gt;&lt;P&gt;Xavier&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 15:34:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-model-tags-whitelist-Should-I-add-tags-used-inside/m-p/613108#M106090</guid>
      <dc:creator>XavG_KS</dc:creator>
      <dc:date>2022-09-14T15:34:13Z</dc:date>
    </item>
  </channel>
</rss>

