<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to find out which data model a particular app maps to? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-find-out-which-data-model-a-particular-app-maps-to/m-p/201986#M1070</link>
    <description>&lt;P&gt;How do I find out which data model a particular app "maps" to?&lt;/P&gt;
&lt;P&gt;Specifically the Cisco security suite ...&lt;/P&gt;
&lt;P&gt;I see it is CIM compatible and need to get that data into my SIEM&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 01:21:27 GMT</pubDate>
    <dc:creator>tmkunte</dc:creator>
    <dc:date>2022-02-10T01:21:27Z</dc:date>
    <item>
      <title>How to find out which data model a particular app maps to?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-find-out-which-data-model-a-particular-app-maps-to/m-p/201986#M1070</link>
      <description>&lt;P&gt;How do I find out which data model a particular app "maps" to?&lt;/P&gt;
&lt;P&gt;Specifically the Cisco security suite ...&lt;/P&gt;
&lt;P&gt;I see it is CIM compatible and need to get that data into my SIEM&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 01:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-find-out-which-data-model-a-particular-app-maps-to/m-p/201986#M1070</guid>
      <dc:creator>tmkunte</dc:creator>
      <dc:date>2022-02-10T01:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: data model - app mapping</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-find-out-which-data-model-a-particular-app-maps-to/m-p/201987#M1071</link>
      <description>&lt;P&gt;The Cisco Security Suite App &lt;A href="https://splunkbase.splunk.com/app/525/"&gt;https://splunkbase.splunk.com/app/525/&lt;/A&gt; searches data from a number of different cisco devices. Many of those devices have their own individual Technology Add-ons. &lt;/P&gt;

&lt;P&gt;Those specific technology add-ons are what you're going to want to look at. They will have tags that determine which data model the data is going to go into. The Splunk Add-on for Cisco ASA is a great example. &lt;A href="https://splunkbase.splunk.com/app/1620/"&gt;https://splunkbase.splunk.com/app/1620/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For more information on which tags go to which data models you can look at specific data models here: &lt;A href="http://docs.splunk.com/Documentation/CIM/latest/User/Overview"&gt;http://docs.splunk.com/Documentation/CIM/latest/User/Overview&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 15:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-find-out-which-data-model-a-particular-app-maps-to/m-p/201987#M1071</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2016-06-09T15:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: data model - app mapping</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-find-out-which-data-model-a-particular-app-maps-to/m-p/584194#M10602</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/174324"&gt;@tmkunte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recently wrote an app (&lt;A href="https://splunkbase.splunk.com/app/6286/" target="_blank" rel="noopener"&gt;Data model wrangler&lt;/A&gt;) that helps with identifying indexes and sourcetypes that are mapped to data models and calculates two scores to determine an overall health-check of mapping:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Mapping quality - Percent of recommended fields in the data model that are found in each index/sourcetype&lt;/LI&gt;&lt;LI&gt;Data quality - Percent coverage of each field within the data, e.g. 25% of events have the 'src' field present&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;It also provides a field-level view of mapped data to determine which fields are present/missing and which fields have a low data quality.&lt;/P&gt;&lt;P&gt;This may help to give a better understanding of what is mapped to each data model. It is also useful when trying to map custom sourcetypes to data models.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 03:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-find-out-which-data-model-a-particular-app-maps-to/m-p/584194#M10602</guid>
      <dc:creator>nvonkorff</dc:creator>
      <dc:date>2022-02-09T03:24:23Z</dc:date>
    </item>
  </channel>
</rss>

