Knowledge Management

Why doesn't my Data map to any Data models?

Will_powr
Explorer

I have logs from switches being ingested, but the data doesn't conform to any standard data model. Is this possible or  

Labels (1)
0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Hi @Will_powr you haven't shown us what your data looks like so it is not as simple as showing you "how". So I will direct you to some background information and the "why" regarding usage of the Splunk Common Information Model CIM and how it works in Splunk (with Data Models)
The What and the Why:
https://docs.splunk.com/Documentation/CIM/5.0.1/User/Overview

The How To:
https://docs.splunk.com/Documentation/CIM/5.0.1/User/Howtousethesereferencetables


It isn't necessary to normalize your data, but if you want your switch data to show up in a Splunk App that utilizes the CIM (maps fields from your data into the data models so that a search using the data model fields will work on your data automagically) you should look into it.

You can also go down this fun looking rabbit hole: https://lantern.splunk.com/Splunk_Platform/Data_Application/Data_Types/Network_switch_data






With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...