Knowledge Management

Is it possible to search against all datamodels for all available sourcetypes in a single query?

att35
Builder

Hi,

While tuning Splunk ES whenever there is a need to see if a datamodel can see required fields from a specific sourcetype, we use the following search

| datamodel Malware search | search sourcetype=<sourcetype>

sourcetype=* works but we still need to specify a datamodel. I was wondering if it is possible to search across all the Datamodels & All sourcetypes at once in a single query? If it is then maybe we can stats by datamodel, sourcetype to get a full picture.

Thanks,

~ Abhi

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...