<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Difference between correlation search written with data modals and correlation search written with normal search query in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-correlation-search-written-with-data-modals/m-p/486065#M8002</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;What is the difference between correlation search created with the datamodals and the correlation search created with normal search query.&lt;/P&gt;

&lt;P&gt;Which is good to follow?&lt;/P&gt;</description>
    <pubDate>Sun, 12 Jan 2020 05:57:39 GMT</pubDate>
    <dc:creator>VijaySrrie</dc:creator>
    <dc:date>2020-01-12T05:57:39Z</dc:date>
    <item>
      <title>Difference between correlation search written with data modals and correlation search written with normal search query</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-correlation-search-written-with-data-modals/m-p/486065#M8002</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;What is the difference between correlation search created with the datamodals and the correlation search created with normal search query.&lt;/P&gt;

&lt;P&gt;Which is good to follow?&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jan 2020 05:57:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-correlation-search-written-with-data-modals/m-p/486065#M8002</guid>
      <dc:creator>VijaySrrie</dc:creator>
      <dc:date>2020-01-12T05:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between correlation search written with data modals and correlation search written with normal search query</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-correlation-search-written-with-data-modals/m-p/486066#M8003</link>
      <description>&lt;P&gt;Both are correlation searches that will ultimately produce notable events.  What they search is completely up to you.  Using a data model typically means the data you think the notable event occurs in, has been normalized to the model.  Using regular indexed data can be slower on performance, but not necessarily.  Imagine querying a very large data model versus a very small index, or even a small lookup table.  One will be faster but both could be "enriched/normalized" with different fields.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jan 2020 12:17:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-correlation-search-written-with-data-modals/m-p/486066#M8003</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-01-12T12:17:40Z</dc:date>
    </item>
  </channel>
</rss>

