Hello,
I have an issue with Endpoint Datamodel while using Enterprise Security.
Specifically I am running:
|rest splunk_server=local /services/datamodel/acceleration |fields title search
Every datamodel has a search string populated except Endpoint.
Is there an explanation for that?
Thank you in advance.
Regards,
Chris
I don't know the answer for sure, but do you need to include the data set? For example: Endpoint.Ports, Endpoint.Processes, Endpoint.Services, or Endpoint.Filesystem?
https://docs.splunk.com/Documentation/CIM/4.18.0/User/Endpoint#Search_Example