- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to exclude some indexes from authentication data model?
We have some indexes such as lastchanceindex, but eventtype was defined within Splunk_TA_nix.
Any clues?
Thanks.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/67508/67508a90a799061aa2ecb53e66dfedcdfe2f82ba" alt="memarshall63 memarshall63"
The indexes to include in each data model are defined within the CIM app (Splunk_SA_CIM).
As an administrator, you can access the Common Information Model app under "Manage Apps" and then select "Setup" -- this takes you to a page that shows the data models configuration. The page address is:
https: //(URL of your Splunk deployment)/en-US/app/Splunk_SA_CIM/cim_setup?action=edit.
Each data model has an "Index Whitelist". By default, this whitelist is set to "All Indexes". You can restrict the data model in that field to only examine your desired indexes.
These whitelisted indexes are then referenced in the macros like cim_Authentication_indexes
in the dataset definitions.
You can find more documentation on this here: https://docs.splunk.com/Documentation/CIM/latest/User/Setup
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/67508/67508a90a799061aa2ecb53e66dfedcdfe2f82ba" alt="memarshall63 memarshall63"
The indexes to include in each data model are defined within the CIM app (Splunk_SA_CIM).
As an administrator, you can access the Common Information Model app under "Manage Apps" and then select "Setup" -- this takes you to a page that shows the data models configuration. The page address is:
https: //(URL of your Splunk deployment)/en-US/app/Splunk_SA_CIM/cim_setup?action=edit.
Each data model has an "Index Whitelist". By default, this whitelist is set to "All Indexes". You can restrict the data model in that field to only examine your desired indexes.
These whitelisted indexes are then referenced in the macros like cim_Authentication_indexes
in the dataset definitions.
You can find more documentation on this here: https://docs.splunk.com/Documentation/CIM/latest/User/Setup
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you recommend to exclude the indexes from the the macro or other workarounds?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/67508/67508a90a799061aa2ecb53e66dfedcdfe2f82ba" alt="memarshall63 memarshall63"
I really don't have a recommendation on 'exclusions'.
I don't know where those macros are referenced, but I would assume they're at the basis of the data model.
Definitely the datasets are established from them. Possibly, acceleration jobs leverage them, too.. Can't say for sure.
Unless you've got a solid reason to the contrary. I'd use the whitelist.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/0e4e4/0e4e49fa1431183490985a6776b7ac74d893b70d" alt="solarboyz1 solarboyz1"
Each of the data models is created using a search string. The default for the Authentication DM is based on the macro cim_Authentication_indexes
Find the macro cim_Authentication_indexes
, and modify it to include or exclude specific indexes.
data:image/s3,"s3://crabby-images/a266d/a266d0c80c12793a952b209c17cc3de41b17fc89" alt=""