<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: found x unexpected values in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/found-x-unexpected-values/m-p/534273#M9596</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223770"&gt;@splunkcol&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;- First you should check index constraints &amp;nbsp;for Network_Traffic model. If this macro is not set, you should set indexes that has traffic data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Install CIM compatible TA's for network traffic sources. (With ES this applies to all sourcetypes that feeds datamodels)&lt;/P&gt;&lt;P&gt;- Even using CIM compatible TA's may not resolve all problems. You should map all invalid values to valid recommended ones (allowed, blocked, teardown) using FIELDALIAS, EVAL or lookups.&lt;/P&gt;&lt;P&gt;You can use&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.18.0/User/NetworkTraffic" target="_blank"&gt;https://docs.splunk.com/Documentation/CIM/4.18.0/User/NetworkTraffic&lt;/A&gt;&amp;nbsp;as a reference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Dec 2020 21:08:28 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2020-12-28T21:08:28Z</dc:date>
    <item>
      <title>found x unexpected values</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/found-x-unexpected-values/m-p/534258#M9595</link>
      <description>&lt;P&gt;I am using the APP "SA-cim_vladiator" and this message appears indicating that it has found unexpected values&lt;/P&gt;&lt;P&gt;In this order of ideas it is only analyzing me and detecting the logs with the action = allowed field&lt;/P&gt;&lt;P&gt;And those that in the value action = Accept or suscces or pass are not detecting them&lt;/P&gt;&lt;P&gt;The same happens for blocked where drop or deny are not detected in the action field&lt;/P&gt;&lt;P&gt;How can I solve this situation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkcol_0-1609175995749.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12377iF16F51DA328BFC26/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunkcol_0-1609175995749.png" alt="splunkcol_0-1609175995749.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2020 17:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/found-x-unexpected-values/m-p/534258#M9595</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2020-12-28T17:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: found x unexpected values</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/found-x-unexpected-values/m-p/534273#M9596</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223770"&gt;@splunkcol&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;- First you should check index constraints &amp;nbsp;for Network_Traffic model. If this macro is not set, you should set indexes that has traffic data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Install CIM compatible TA's for network traffic sources. (With ES this applies to all sourcetypes that feeds datamodels)&lt;/P&gt;&lt;P&gt;- Even using CIM compatible TA's may not resolve all problems. You should map all invalid values to valid recommended ones (allowed, blocked, teardown) using FIELDALIAS, EVAL or lookups.&lt;/P&gt;&lt;P&gt;You can use&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.18.0/User/NetworkTraffic" target="_blank"&gt;https://docs.splunk.com/Documentation/CIM/4.18.0/User/NetworkTraffic&lt;/A&gt;&amp;nbsp;as a reference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2020 21:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/found-x-unexpected-values/m-p/534273#M9596</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-28T21:08:28Z</dc:date>
    </item>
  </channel>
</rss>

