Knowledge Management

Malware_attacks dataset is not showing event under Malware Datamodel

rashid47010
Communicator

Dear Experts,

there are no events for "Malware"."Malware_attacks".

tags and eventtypes seems fine
but there are no events when I select
tag=malware in the search.

how can I troubleshoot Malware Datamodel issue.

Tags (1)
0 Karma
1 Solution

koshyk
Super Champion

Ok, there are few moving parts for displaying the tags

  1. Splunk CIM => https://docs.splunk.com/Documentation/CIM/4.13.0/User/Malware
  2. The Addon/TA which contains logic to extract the tags
  3. Your data/sourcetype

You need all of the above for the tag to show properly. So inorder to debug
a. Ensure your data/sourcetype contains malware type of events. Check if this sourcetype is used by the relevant Addon/TA
b. Go into the TA and check for props.conf, transforms.conf, eventtypes.conf & tags.conf. See if they are extracting properly from your data. Test this in DEV
c. If (a) and (b) is all good, then ensure your CIM app/addon is correct version.
d. Check for datamodels and its acceleration

View solution in original post

0 Karma

koshyk
Super Champion

Ok, there are few moving parts for displaying the tags

  1. Splunk CIM => https://docs.splunk.com/Documentation/CIM/4.13.0/User/Malware
  2. The Addon/TA which contains logic to extract the tags
  3. Your data/sourcetype

You need all of the above for the tag to show properly. So inorder to debug
a. Ensure your data/sourcetype contains malware type of events. Check if this sourcetype is used by the relevant Addon/TA
b. Go into the TA and check for props.conf, transforms.conf, eventtypes.conf & tags.conf. See if they are extracting properly from your data. Test this in DEV
c. If (a) and (b) is all good, then ensure your CIM app/addon is correct version.
d. Check for datamodels and its acceleration

0 Karma
Get Updates on the Splunk Community!

Harnessing Splunk’s Federated Search for Amazon S3

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated ...

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...