<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enterprise Security: How to get a field break-down for a Web datamodel? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475472#M7452</link>
    <description>&lt;P&gt;I know the field names @ChrisG, if this is what you meant, but I like to see a breakdown of the fields, since there are quite a bit of them.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2019 15:23:55 GMT</pubDate>
    <dc:creator>danielbb</dc:creator>
    <dc:date>2019-09-11T15:23:55Z</dc:date>
    <item>
      <title>Enterprise Security: How to get a field break-down for a Web datamodel?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475470#M7450</link>
      <description>&lt;P&gt;I'm looking at the &lt;EM&gt;Web&lt;/EM&gt; datamodel and try to determine which fields are populated. &lt;/P&gt;

&lt;P&gt;I can do :&lt;BR /&gt;
&lt;CODE&gt;| tstats  dc(sourcetype) FROM datamodel=Web by sourcetype&lt;/CODE&gt; &lt;BR /&gt;
and  &lt;CODE&gt;| tstats  count(sourcetype) &lt;BR /&gt;
FROM datamodel=Web by sourcetype&lt;/CODE&gt; or &lt;BR /&gt;
&lt;CODE&gt;| tstats  count(Web.status) FROM datamodel=Web by Web.status&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;but I like to see a breakdown of all the fields in this datamodel. &lt;/P&gt;

&lt;P&gt;Is it possible? &lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 14:58:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475470#M7450</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-09-11T14:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security: How to get a field break-down for a Web datamodel?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475471#M7451</link>
      <description>&lt;P&gt;You can refer to the Common Information Model documentation. See &lt;A href="https://docs.splunk.com/Documentation/CIM/4.13.0/User/Web"&gt;https://docs.splunk.com/Documentation/CIM/4.13.0/User/Web&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 15:19:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475471#M7451</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2019-09-11T15:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security: How to get a field break-down for a Web datamodel?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475472#M7452</link>
      <description>&lt;P&gt;I know the field names @ChrisG, if this is what you meant, but I like to see a breakdown of the fields, since there are quite a bit of them.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 15:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475472#M7452</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-09-11T15:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security: How to get a field break-down for a Web datamodel?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475473#M7453</link>
      <description>&lt;P&gt;I guess I'm not sure what you mean by "breakdown." The doc lists the field names, data type, description, and example values. Can you clarify your question, to help the community answer better?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 15:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475473#M7453</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2019-09-11T15:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security: How to get a field break-down for a Web datamodel?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475474#M7454</link>
      <description>&lt;P&gt;Sure, I would like to see which fields are populated with which values across all the fields which are available in this datamodel, without examining each field individually. I hope it's clear.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 15:42:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475474#M7454</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-09-11T15:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security: How to get a field break-down for a Web datamodel?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475475#M7455</link>
      <description>&lt;P&gt;I guess the pivot is a good place to explore the datamodel. &lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 13:17:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-How-to-get-a-field-break-down-for-a-Web/m-p/475475#M7455</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-09-12T13:17:19Z</dc:date>
    </item>
  </channel>
</rss>

