All Apps and Add-ons

Data Model Network_Traffic doesn't work

ahsaine
New Member

I am new on Splunk. I am using Infosec app and I have question please.
I am getting logs from the firewall after executing this command: | datamodel Network_Traffic All_Traffic search
But the Network_Traffic data model doesn't show any results after this request: | tstats summariesonly=true allow_old_summaries=true count from datamodel=Network_Traffic.All_Traffic where (All_Traffic.action=blocked OR All_Traffic.action=deny)
Any idea how to resolve this??

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The tstats command doesn't like datasets in the datamodel option. Use the nodename option, instead.

... | tstats summariesonly=true allow_old_summaries=true count from datamodel=Network_Traffic where nodename=Network_Traffic.All_Traffic  (All_Traffic.action=blocked OR All_Traffic.action=deny)
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...