Other Usage

datamodel showing unknown with stats or tstats for dest field

Chiranjeev
Explorer

HI ,

I have a Web data model where i recently got it mapped with the dest field.the issue is that event hough every filed has a dest in the index from where i am pulling data in datamodel i still see alot of fields with value unknown for dest  while running stats or tstats command .I can see the the dest field when i specifically search it within a datamodel with a src ip . can anyone help to tell how do i rectify that .

 

Thanks.

0 Karma

Gr0und_Z3r0
Contributor

hi @Chiranjeev 

The default configuration in web datamodel for dest field is evaluated.

if(isnull(dest) OR dest="" OR dest="-","unknown",dest)

So you'll need to either update this eval statement in the data model to fit your case or map correct field for dest field.

If the reply helps, a Karma vote would be appreciated. 

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...