<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to know all the Contents created from a specific data model in Splunk Enterprise Security ? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571491#M10390</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237518"&gt;@zacksoft_wf&lt;/a&gt;&amp;nbsp; If you already know your sourcetypes, try follow this post - this may help you to get the relevant KOs : &lt;A href="https://community.splunk.com/t5/Security/Sourcetypes-list-of-where-they-re-being-used/m-p/306682" target="_blank"&gt;https://community.splunk.com/t5/Security/Sourcetypes-list-of-where-they-re-being-used/m-p/306682&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Keen to know how you go with this.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Oct 2021 10:15:51 GMT</pubDate>
    <dc:creator>dwickram</dc:creator>
    <dc:date>2021-10-19T10:15:51Z</dc:date>
    <item>
      <title>How to know all the Contents created from a specific data model in Splunk Enterprise Security ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571278#M10383</link>
      <description>&lt;P&gt;I want to list all the 'Authentication' related content we have created in the ES App.&lt;BR /&gt;Is there any SPL query to get this.&lt;BR /&gt;Need to list all the dashboards, Notable Events etc... of Authentication type.&lt;BR /&gt;I would really appreciate any help.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 08:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571278#M10383</guid>
      <dc:creator>zacksoft_wf</dc:creator>
      <dc:date>2021-10-18T08:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to know all the Contents created from a specific data model in Splunk Enterprise Security ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571332#M10384</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237518"&gt;@zacksoft_wf&lt;/a&gt;&amp;nbsp; Hi there, not sure if just one SPL can give all the stats you're after, but if you navigate to Configure --&amp;gt; Content Management --&amp;gt;&amp;nbsp; And on Search window type "Authentication", this gives a list of items configured under Authentication. Did you try this already OR you need still need a SPL to query a statistical view?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 13:10:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571332#M10384</guid>
      <dc:creator>dwickram</dc:creator>
      <dc:date>2021-10-18T13:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to know all the Contents created from a specific data model in Splunk Enterprise Security ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571337#M10385</link>
      <description>&lt;P&gt;I was thinking , if I have my sourcetypes names with me, Can we build a query that can scan _internal log or something and tell me in which contents (dashboard, Correlation Searches etc, ) this sourcetype is used . That could help too.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 13:35:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571337#M10385</guid>
      <dc:creator>zacksoft_wf</dc:creator>
      <dc:date>2021-10-18T13:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to know all the Contents created from a specific data model in Splunk Enterprise Security ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571357#M10386</link>
      <description>&lt;P&gt;I don't think so. Remember that you can reference objects using macros so even if you listed all configuration and user content and searched through it for your data model, you wouldn't find occurences of macros defined with that datamodel. And that could possibly involve another macro. And so on.&lt;/P&gt;&lt;P&gt;So there can be some approximate methods but I don't see a 100% reliable way.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 15:04:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571357#M10386</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-18T15:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to know all the Contents created from a specific data model in Splunk Enterprise Security ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571472#M10388</link>
      <description>&lt;P&gt;SPL query with statistical view would be helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 07:26:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571472#M10388</guid>
      <dc:creator>zacksoft_wf</dc:creator>
      <dc:date>2021-10-19T07:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to know all the Contents created from a specific data model in Splunk Enterprise Security ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571473#M10389</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; &amp;nbsp;hmm.. That makes sense. thanks for the input.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 07:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571473#M10389</guid>
      <dc:creator>zacksoft_wf</dc:creator>
      <dc:date>2021-10-19T07:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to know all the Contents created from a specific data model in Splunk Enterprise Security ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571491#M10390</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237518"&gt;@zacksoft_wf&lt;/a&gt;&amp;nbsp; If you already know your sourcetypes, try follow this post - this may help you to get the relevant KOs : &lt;A href="https://community.splunk.com/t5/Security/Sourcetypes-list-of-where-they-re-being-used/m-p/306682" target="_blank"&gt;https://community.splunk.com/t5/Security/Sourcetypes-list-of-where-they-re-being-used/m-p/306682&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Keen to know how you go with this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 10:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-know-all-the-Contents-created-from-a-specific-data-model/m-p/571491#M10390</guid>
      <dc:creator>dwickram</dc:creator>
      <dc:date>2021-10-19T10:15:51Z</dc:date>
    </item>
  </channel>
</rss>

