Splunk Enterprise Security

Query on Data models

xoriantkbisht
Explorer

HI Team,
I have query regarding Data models base search

| multisearch [| from datamodel:Endpoint.Filesystem | search tag="change" ] [| from datamodel:Endpoint.Registry | search tag="change" ] [| from datamodel:Change.Endpoint_Changes | search ] | head 100

Above is the query for "Recent Endpoint Changes" in Endpoint Changes Dashboard (Splunk Enterprise Security (Endpoint Security Domain))

Now query refers to Endpoint.Filesystem data model. This data model includes cim_Endpoint_indexes macros which refers to index=crowstrike in my environment and 2 tags as tag=filesystem and tag=endpoint. These tags are filled with eventtypes where sourcetypes are specified. Now one of the eventtype refers to sourcetype as aws:cloudtrail.

And whatever result i am getting for above query is related to aws:cloudtrail only.

Now my understanding is when you are referring to data model in your query then it should gives you results from specified index and in this case index=crowdstrike sourcetype=aws:cloudtrail is invalid but still above search is populating results in dashboard

In short data models base search is not fulfilling the specified fields but still results are getting populated

Could you please correct my understandings.

0 Karma

codebuilder
Influencer

Datamodels can contain data from multiple indexes. They're not restricted to a single index or sourcetype.

You can easily find all the indexes and sourcetypes associated with a given datamodel with the following:

| tstats count from datamodel=your_datamodel_name by index, sourcetype
----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...