All Apps and Add-ons

How do I fix DLP datamodel with one Event it self?

AL3Z
Builder

Hi,

I didnt see any fields from the dlp datamodel apart from 1 event ,what we fix this to get all the fields and events ?

 

 

 

Labels (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@AL3Z - I can see you are searching for last 30 minutes only. Try increasing the timerange to see if you have more details.

 

I hope this helps!!!

0 Karma

AL3Z
Builder

Hi Vatsal,

Even if we search for  24 hours or 7days it is showing the same output.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@AL3Z - You need to check the events field extraction for data-model mapping.

You can use this for learning - https://www.youtube.com/watch?v=cJw3IAgbBV0

 

I hope this helps!!!

AL3Z
Builder

Hi,
If I  use the |datamodel DLP DLP_Incidents search its populating all the fields with out search  at the end its not giving all the fields why ?

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

That's how the datamodel command should work. Read more here - https://docs.splunk.com/Documentation/Splunk/9.0.4/SearchReference/Datamodel#.26lt.3Bdata_model_sear...

 

I hope this helps!!! 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...