Getting Data In

Intrusion Detection data model: Is host not really a tag, but treated as such with regard to the data model?

tmkunte
Engager

This is more of question for my understanding...

In the examples section of CIM Add-on manual (for OSSEC) there is a statement that the Intrusion Detection data model requires the tags ids, attack, and host

If you look at the intrusion detection data model, the constraint is ids_type="host"

So host is not really a tag, but it is treated as such with regards to the data model?

thanks

rpille_splunk
Splunk Employee
Splunk Employee

tmkunte -- thanks for pointing this out. That is a docs bug. We should only be referring to ids and attack as tags. The additional constraint for a host intrusion detection is the presence of that ids_type field with a value of host, as you point out. We'll get it fixed!

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...