Knowledge Management

Feeding data into a data model

bseppanen1
Explorer

I'm working with a standalone splunk 8.1.3 instance with the Splunk CIM 4.20.2.      I have several accelerated data models that are populating data properly.    I have a couple of data sources,specifically an ISC DHCP server logging to a custom UDP port, and a Palo Alto firewall which is logging to its own index, that I'm not finding the data within the data model.   pan:traffic from the palo alto index should constitute network session data, and the ISC DHCP data should likewise.     Is there a way to find out why that data isn't being categorized in that manner?      Is there some way I can get that data in there properly?

 

Thanks,

 

Labels (1)
0 Karma

bseppanen1
Explorer

So i did discover that there is a splunk add on specific to ISC DHCP and I did install that.    That add on doesn't seem to be CIM 4 compliant, so it appears I would have to do that lifting myself and worry that I will implement an Un-Common information model by doing so.     Thanks for your response.

 

It turns out that ISC DHCP Plugin does Support CIM definitions, so I just had to redefine the sourcetype for that to happen properly.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The key to getting data into a datamodel is to make sure the incoming data uses CIM fields.  Installing the CIM app isn't enough.  You may have to add EVALs or FIELDALIASes to props.conf for the appropriate sourcetypes.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...