Knowledge Management

Malware_attacks dataset is not showing event under Malware Datamodel

rashid47010
Communicator

Dear Experts,

there are no events for "Malware"."Malware_attacks".

tags and eventtypes seems fine
but there are no events when I select
tag=malware in the search.

how can I troubleshoot Malware Datamodel issue.

Tags (1)
0 Karma
1 Solution

koshyk
Super Champion

Ok, there are few moving parts for displaying the tags

  1. Splunk CIM => https://docs.splunk.com/Documentation/CIM/4.13.0/User/Malware
  2. The Addon/TA which contains logic to extract the tags
  3. Your data/sourcetype

You need all of the above for the tag to show properly. So inorder to debug
a. Ensure your data/sourcetype contains malware type of events. Check if this sourcetype is used by the relevant Addon/TA
b. Go into the TA and check for props.conf, transforms.conf, eventtypes.conf & tags.conf. See if they are extracting properly from your data. Test this in DEV
c. If (a) and (b) is all good, then ensure your CIM app/addon is correct version.
d. Check for datamodels and its acceleration

View solution in original post

0 Karma

koshyk
Super Champion

Ok, there are few moving parts for displaying the tags

  1. Splunk CIM => https://docs.splunk.com/Documentation/CIM/4.13.0/User/Malware
  2. The Addon/TA which contains logic to extract the tags
  3. Your data/sourcetype

You need all of the above for the tag to show properly. So inorder to debug
a. Ensure your data/sourcetype contains malware type of events. Check if this sourcetype is used by the relevant Addon/TA
b. Go into the TA and check for props.conf, transforms.conf, eventtypes.conf & tags.conf. See if they are extracting properly from your data. Test this in DEV
c. If (a) and (b) is all good, then ensure your CIM app/addon is correct version.
d. Check for datamodels and its acceleration

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...