<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wrong values in the field within data model in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Wrong-values-in-the-field-within-data-model/m-p/540706#M153002</link>
    <description>&lt;P&gt;Are you referring to the Registry data set in the Endpoint data model?&lt;/P&gt;&lt;P&gt;If your data is incorrect, you have field aliases, calculated fields, or field extractions on &lt;EM&gt;tag=endpoint tag=registry&amp;nbsp;&lt;/EM&gt;events that produce incorrect results. This could include automatic extractions on raw event text like "user=foo.exe."&lt;/P&gt;&lt;P&gt;Start by determining which field-value pairs identify &lt;EM&gt;tag=registry&lt;/EM&gt;. You can use Settings &amp;gt; Tags &amp;gt; List by tag name in the UI or run 'splunk cmd btool tags list --debug' on your instance. From there, review and correct knowledge objects for the related events.&lt;/P&gt;&lt;P&gt;You can rebuild the data model or leave old, incorrect data in place while new events populate the data model correctly going forward, depending on your requirements.&lt;/P&gt;</description>
    <pubDate>Sun, 21 Feb 2021 07:01:50 GMT</pubDate>
    <dc:creator>tscroggins</dc:creator>
    <dc:date>2021-02-21T07:01:50Z</dc:date>
    <item>
      <title>Wrong values in the field within data model</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Wrong-values-in-the-field-within-data-model/m-p/537595#M151998</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm searching through the Registry data model and I noticed that in the field "user" I've got process names. How to fix it?&lt;/P&gt;&lt;P&gt;As far as I know, after fixing it - so in the "user" field there is actually a user name, I will need to rebuild the whole data model, right?&lt;/P&gt;&lt;P&gt;Will I need to take some extra steps if this data model is accelerated?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 10:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Wrong-values-in-the-field-within-data-model/m-p/537595#M151998</guid>
      <dc:creator>fedejko</dc:creator>
      <dc:date>2021-01-28T10:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Wrong values in the field within data model</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Wrong-values-in-the-field-within-data-model/m-p/540706#M153002</link>
      <description>&lt;P&gt;Are you referring to the Registry data set in the Endpoint data model?&lt;/P&gt;&lt;P&gt;If your data is incorrect, you have field aliases, calculated fields, or field extractions on &lt;EM&gt;tag=endpoint tag=registry&amp;nbsp;&lt;/EM&gt;events that produce incorrect results. This could include automatic extractions on raw event text like "user=foo.exe."&lt;/P&gt;&lt;P&gt;Start by determining which field-value pairs identify &lt;EM&gt;tag=registry&lt;/EM&gt;. You can use Settings &amp;gt; Tags &amp;gt; List by tag name in the UI or run 'splunk cmd btool tags list --debug' on your instance. From there, review and correct knowledge objects for the related events.&lt;/P&gt;&lt;P&gt;You can rebuild the data model or leave old, incorrect data in place while new events populate the data model correctly going forward, depending on your requirements.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 07:01:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Wrong-values-in-the-field-within-data-model/m-p/540706#M153002</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2021-02-21T07:01:50Z</dc:date>
    </item>
  </channel>
</rss>

