Splunk Enterprise Security

Splunk CIM mismatch type for tags

DEAD_BEEF
Builder

Not sure how to fix this, but for some reason the tags showing up in
Search > Datasets > Intrusion Detection > IDS Attacks > Summarize Fields
shows a mismatched type. Splunk docs shows that this should be a string field. The tag itself is generated from an Event type search, so I'm not sure why it would be anything other than string. Any insight?

alt text

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...