<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error in model &amp;quot;JVM&amp;quot; : Cannot add field 'cpu_time_supported' because it already exists in object 'Threading'. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Error-in-model-quot-JVM-quot-Cannot-add-field-cpu-time-supported/m-p/112771#M29647</link>
    <description>&lt;P&gt;hi !!! i got this error when trying to create a data model:"Error in model "JVM" : Cannot add field 'cpu_time_supported' because it already exists in object 'Threading'". &lt;BR /&gt;
I don't understand it . could someone explain it to me and show me a way to fix it ?&lt;BR /&gt;
Thank you ..&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 17:30:02 GMT</pubDate>
    <dc:creator>jeandez</dc:creator>
    <dc:date>2020-09-28T17:30:02Z</dc:date>
    <item>
      <title>Error in model "JVM" : Cannot add field 'cpu_time_supported' because it already exists in object 'Threading'.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-model-quot-JVM-quot-Cannot-add-field-cpu-time-supported/m-p/112771#M29647</link>
      <description>&lt;P&gt;hi !!! i got this error when trying to create a data model:"Error in model "JVM" : Cannot add field 'cpu_time_supported' because it already exists in object 'Threading'". &lt;BR /&gt;
I don't understand it . could someone explain it to me and show me a way to fix it ?&lt;BR /&gt;
Thank you ..&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-model-quot-JVM-quot-Cannot-add-field-cpu-time-supported/m-p/112771#M29647</guid>
      <dc:creator>jeandez</dc:creator>
      <dc:date>2020-09-28T17:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Error in model "JVM" : Cannot add field 'cpu_time_supported' because it already exists in object 'Threading'.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-model-quot-JVM-quot-Cannot-add-field-cpu-time-supported/m-p/112772#M29648</link>
      <description>&lt;P&gt;We are also noticing the same on the SH's which also have ES installed. has any one fout out the solution to fix this? We are running 6.1.5 on SHP. &lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2015 17:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-model-quot-JVM-quot-Cannot-add-field-cpu-time-supported/m-p/112772#M29648</guid>
      <dc:creator>bohrasaurabh</dc:creator>
      <dc:date>2015-06-01T17:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Error in model "JVM" : Cannot add field 'cpu_time_supported' because it already exists in object 'Threading'.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-model-quot-JVM-quot-Cannot-add-field-cpu-time-supported/m-p/112773#M29649</link>
      <description>&lt;P&gt;This was a bug in ES 3.0.0 which was addressed in ES 3.0.1.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 13:54:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-model-quot-JVM-quot-Cannot-add-field-cpu-time-supported/m-p/112773#M29649</guid>
      <dc:creator>jcrabb_splunk</dc:creator>
      <dc:date>2015-06-10T13:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Error in model "JVM" : Cannot add field 'cpu_time_supported' because it already exists in object 'Threading'.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-model-quot-JVM-quot-Cannot-add-field-cpu-time-supported/m-p/112774#M29650</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I noticed that in the data model editor in general you cannot overwrite fields that exist in a) the events or b) the parent object of the data model object you want to define that field.&lt;/P&gt;

&lt;P&gt;I would consider this as a bug (since you can do overwrite existing fields in a regular search) and it is not limited to the Enterprise Security app.&lt;/P&gt;

&lt;P&gt;In general overwriting fields is a nice (the only?) way to apply multiple transfomations (eval, lookups, rex, etc.) on a field to 'enhance' its value.&lt;/P&gt;

&lt;P&gt;We are using Splunk 6.1.2. Is this fixed in a newer version?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 13:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-model-quot-JVM-quot-Cannot-add-field-cpu-time-supported/m-p/112774#M29650</guid>
      <dc:creator>fDK</dc:creator>
      <dc:date>2015-07-07T13:52:31Z</dc:date>
    </item>
  </channel>
</rss>

