I am new on Splunk. I am using Infosec app and I have question please.
I am getting logs from the firewall after executing this command: | datamodel Network_Traffic All_Traffic search
But the Network_Traffic data model doesn't show any results after this request: | tstats summariesonly=true allow_old_summaries=true count from datamodel=Network_Traffic.All_Traffic where (All_Traffic.action=blocked OR All_Traffic.action=deny)
Any idea how to resolve this??
The tstats
command doesn't like datasets in the datamodel
option. Use the nodename
option, instead.
... | tstats summariesonly=true allow_old_summaries=true count from datamodel=Network_Traffic where nodename=Network_Traffic.All_Traffic (All_Traffic.action=blocked OR All_Traffic.action=deny)