Splunk Enterprise Security

Difference between correlation search written with data modals and correlation search written with normal search query

VijaySrrie
Builder

Hi Team,

What is the difference between correlation search created with the datamodals and the correlation search created with normal search query.

Which is good to follow?

1 Solution

jkat54
SplunkTrust
SplunkTrust

Both are correlation searches that will ultimately produce notable events. What they search is completely up to you. Using a data model typically means the data you think the notable event occurs in, has been normalized to the model. Using regular indexed data can be slower on performance, but not necessarily. Imagine querying a very large data model versus a very small index, or even a small lookup table. One will be faster but both could be "enriched/normalized" with different fields.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Both are correlation searches that will ultimately produce notable events. What they search is completely up to you. Using a data model typically means the data you think the notable event occurs in, has been normalized to the model. Using regular indexed data can be slower on performance, but not necessarily. Imagine querying a very large data model versus a very small index, or even a small lookup table. One will be faster but both could be "enriched/normalized" with different fields.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...