Knowledge Management

How to enrich "index" field in any datamodel?

mdey
New Member

I have a data model where I want to enrich "index" field. I m very new to datamodel section and reading docs to gain some knowledge. Any sort of help or reference will be appreciated.

Thanks & Regards.

Tags (1)
0 Karma

mayurr98
Super Champion

go to datamodel>create_new>add dataset>root event>constraints and in constraints write index=<your_index>

this is how you can enrich a specific index in a data model.

If this does not answer your question, then can you please be specific about what do you want?

Let me know if you need any help!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...