Splunk Enterprise Security

Datamodel Search is empty

b_chris21
Communicator

Hello,

I have an issue with Endpoint Datamodel while using Enterprise Security.

Specifically I am running:

 

 

|rest splunk_server=local /services/datamodel/acceleration |fields title search

 

 

Every datamodel has a search string populated except Endpoint.

Is there an explanation for that? 

Thank you in advance.

Regards,

Chris

Labels (1)
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

I don't know the answer for sure, but do you need to include the data set? For example: Endpoint.Ports, Endpoint.Processes, Endpoint.Services, or Endpoint.Filesystem?

https://docs.splunk.com/Documentation/CIM/4.18.0/User/Endpoint#Search_Example

0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...