Knowledge Management

Is it possible to search against all datamodels for all available sourcetypes in a single query?

att35
Builder

Hi,

While tuning Splunk ES whenever there is a need to see if a datamodel can see required fields from a specific sourcetype, we use the following search

| datamodel Malware search | search sourcetype=<sourcetype>

sourcetype=* works but we still need to specify a datamodel. I was wondering if it is possible to search across all the Datamodels & All sourcetypes at once in a single query? If it is then maybe we can stats by datamodel, sourcetype to get a full picture.

Thanks,

~ Abhi

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...