Knowledge Management

Datamodel issues

damode
Motivator

When I pivot a particular datamodel, I get this error, "Datamodel 'Splunk_CIM_Validation.Vulnerabilities' had an invalid search, cannot get indexes to search"

After inspecting the search.log, I noticed these two error messsages.

07-08-2020 20:16:24.484 ERROR AdminManagerValidation - 'undefineduundefined' is not a time string.
07-08-2020 20:16:24.484 ERROR DataModelValidator - 'undefineduundefined' is not a time string.

Can someone please help how to fix this issue ?

Labels (1)
0 Karma
1 Solution

damode
Motivator

Thanks for your help. I was able to fix the issue by disabling the datamodel acceleration which was still stuck on "building" status.

View solution in original post

0 Karma

misterduke
Explorer

Hello,

 

here is a similar topic. did you try those steps? 

in a nutshell you should check the datamodel and the macro and look what's in it. if the datamodel uses a macro and this particular macro tries to search an index that doesn't exist, you get an error. if the SPL within the datamodel/macro lacks something, you get an error.

 

you can expand macros btw with STRG (or command)+Shift+E

 

hope that helps

0 Karma

damode
Motivator

Thanks for your help. I was able to fix the issue by disabling the datamodel acceleration which was still stuck on "building" status.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...