Splunk Enterprise Security

Datamodel status building since long

snigdhasaxena
Communicator

I have Email datamodel that ships alongwith Splunk ES. It's in building status and it's accelerated too. How to troubleshoot it ?
Does it depends on any lookups ? after checking constraints, I can see macros and tags.. and no lookups.

0 Karma

harsmarvania57
Ultra Champion

Have you configured indexes for Email datamodel (It's in CIM app setup page). By default CIM datamodels will try to read data from all indexes, so as best practice it will be good to limit datamodel for required indexes only.

snigdhasaxena
Communicator

When I look at constraints, it has macro that has definition , index=NULL, I was suspecting that's the error.. so I had changed the constraint to index=* but it still doesn't work

0 Karma

harsmarvania57
Ultra Champion

You need to specify only those indexes which required for that datamodel, index=* will search all the indexes and due to that it takes long time to complete search and this will result in datamodel is in build state.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...