Knowledge Management

Why doesn't my Data map to any Data models?

Will_powr
Explorer

I have logs from switches being ingested, but the data doesn't conform to any standard data model. Is this possible or  

Labels (1)
0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Hi @Will_powr you haven't shown us what your data looks like so it is not as simple as showing you "how". So I will direct you to some background information and the "why" regarding usage of the Splunk Common Information Model CIM and how it works in Splunk (with Data Models)
The What and the Why:
https://docs.splunk.com/Documentation/CIM/5.0.1/User/Overview

The How To:
https://docs.splunk.com/Documentation/CIM/5.0.1/User/Howtousethesereferencetables


It isn't necessary to normalize your data, but if you want your switch data to show up in a Splunk App that utilizes the CIM (maps fields from your data into the data models so that a search using the data model fields will work on your data automagically) you should look into it.

You can also go down this fun looking rabbit hole: https://lantern.splunk.com/Splunk_Platform/Data_Application/Data_Types/Network_switch_data






With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...