<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Feeding data into a data model in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Feeding-data-into-a-data-model/m-p/569765#M8530</link>
    <description>&lt;P&gt;I'm working with a standalone splunk 8.1.3 instance with the Splunk CIM 4.20.2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have several accelerated data models that are populating data properly.&amp;nbsp;&amp;nbsp;&amp;nbsp; I have a couple of data sources,specifically an ISC DHCP server logging to a custom UDP port, and a Palo Alto firewall which is logging to its own index, that I'm not finding the data within the data model.&amp;nbsp;&amp;nbsp; pan:traffic from the palo alto index should constitute network session data, and the ISC DHCP data should likewise.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is there a way to find out why that data isn't being categorized in that manner?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is there some way I can get that data in there properly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Oct 2021 18:49:22 GMT</pubDate>
    <dc:creator>bseppanen1</dc:creator>
    <dc:date>2021-10-05T18:49:22Z</dc:date>
    <item>
      <title>Feeding data into a data model</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Feeding-data-into-a-data-model/m-p/569765#M8530</link>
      <description>&lt;P&gt;I'm working with a standalone splunk 8.1.3 instance with the Splunk CIM 4.20.2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have several accelerated data models that are populating data properly.&amp;nbsp;&amp;nbsp;&amp;nbsp; I have a couple of data sources,specifically an ISC DHCP server logging to a custom UDP port, and a Palo Alto firewall which is logging to its own index, that I'm not finding the data within the data model.&amp;nbsp;&amp;nbsp; pan:traffic from the palo alto index should constitute network session data, and the ISC DHCP data should likewise.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is there a way to find out why that data isn't being categorized in that manner?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is there some way I can get that data in there properly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 18:49:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Feeding-data-into-a-data-model/m-p/569765#M8530</guid>
      <dc:creator>bseppanen1</dc:creator>
      <dc:date>2021-10-05T18:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Feeding data into a data model</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Feeding-data-into-a-data-model/m-p/569776#M8531</link>
      <description>&lt;P&gt;The key to getting data into a datamodel is to make sure the incoming data uses CIM fields.&amp;nbsp; Installing the CIM app isn't enough.&amp;nbsp; You may have to add EVALs or FIELDALIASes to props.conf for the appropriate sourcetypes.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 19:30:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Feeding-data-into-a-data-model/m-p/569776#M8531</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-05T19:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Feeding data into a data model</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Feeding-data-into-a-data-model/m-p/570205#M8532</link>
      <description>&lt;P&gt;So i did discover that there is a splunk add on specific to ISC DHCP and I did install that.&amp;nbsp;&amp;nbsp;&amp;nbsp; That add on doesn't seem to be CIM 4 compliant, so it appears I would have to do that lifting myself and worry that I will implement an Un-Common information model by doing so.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It turns out that ISC DHCP Plugin does Support CIM definitions, so I just had to redefine the sourcetype for that to happen properly.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 20:42:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Feeding-data-into-a-data-model/m-p/570205#M8532</guid>
      <dc:creator>bseppanen1</dc:creator>
      <dc:date>2021-10-08T20:42:47Z</dc:date>
    </item>
  </channel>
</rss>

