Getting Data In

Intrusion Detection data model: Is host not really a tag, but treated as such with regard to the data model?


This is more of question for my understanding...

In the examples section of CIM Add-on manual (for OSSEC) there is a statement that the Intrusion Detection data model requires the tags ids, attack, and host

If you look at the intrusion detection data model, the constraint is ids_type="host"

So host is not really a tag, but it is treated as such with regards to the data model?


Splunk Employee
Splunk Employee

tmkunte -- thanks for pointing this out. That is a docs bug. We should only be referring to ids and attack as tags. The additional constraint for a host intrusion detection is the presence of that ids_type field with a value of host, as you point out. We'll get it fixed!

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...