Knowledge Management

Pre-defined Data Models

rmck2012
New Member

Does anybody know if there are pre-defined or common data models that are documented somewhere that could be used as a guide to assist with building data models for those of us who are less familiar with that process?

For example, I would think there are numerous common data sources where a basic guide could be created to walk users who are new to Splunk 6 through the process of building a usable data model.

These common data sources could include things such as:

  • Cisco ASA logs
  • Microsoft domain controller security event logs
  • Web filter logs, such as from a Cisco Ironport or Barracuda web filter
  • Network infrastructure devices, such as Cisco switch and router logs

These are just a few, but it could be useful as a starting point to get users familiar with the process of creating and using data models in Splunk 6.

Thank you,

Rick

Tags (2)
0 Karma

araitz
Splunk Employee
Splunk Employee

Check out the Splunk Common Information Model app here:

http://apps.splunk.com/app/1621/

See the documentation here:

http://docs.splunk.com/Documentation/CIM/latest/User/RelationshipofCIMappstodata

Let us know what other data sources you would like to see data models for.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...