Getting Data In

Getting new index data into data model

ygoltsev
Engager

Hi - I am trying to configure the authentication data model to include additional source data indexes.

We want to include Duo logs in our dashboard in Splunk ES, but am unsure how to get the data model to recognize the new data.  The logs also appear to be in a different format, but I notice there's a method to "eval" the fields in the data model.  Can you please advise best practice for this? 

Thanks.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The first step is to make sure the Duo logs are CIM-compliant.  Check the manual at https://docs.splunk.com/Documentation/CIM/4.20.0/User/Authentication to see what fields the DM expects.  Add FIELDALIAS and other settings to props.conf to create those fields.  It's not necessary to have all of them, but you'll want to have the fields your ES use cases need.

Once that's done, go to ES's Settings menu and select "CIM Setup".  Add the Duo index to the list of indexes used by the Authentication datamodel and click Save.  Wait for the DM to rebuild and check the results.

---
If this reply helps you, Karma would be appreciated.

ygoltsev
Engager

This is helpful thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...