Splunk Enterprise Security

Why aren't my IDS logs populating the Intrusion Detection data model?

DEAD_BEEF
Builder

I am using Splunk ES and trying to match my IDS logs to the Intrusion Detection data model. I thought I did all preparatory steps required but when clicking in the ES app Search > Datasets > Intrusion Detection > IDS Attacks > Summarize Fields nearly all the of the fields are listed as "null or empty" and the few that are populated contain "unknown" in them.

Here is what I have done so far:

  1. Created event type search to identify the logs and tag them as "ids" and "attack" per CIM docs (shared globally)
  2. Created field aliases (shared globally) as most of my existing logs are named something other than the expected datamodel field name

alt text
3. Validating the data per step 6A
4. End result mostly null or unknownalt text

0 Karma
1 Solution

DEAD_BEEF
Builder

The way to fix this is I had to rename the field aliases to the data model field name that's listed in the docs (go figure) rather than what was showing up in search (see below)
alt text

View solution in original post

DEAD_BEEF
Builder

The way to fix this is I had to rename the field aliases to the data model field name that's listed in the docs (go figure) rather than what was showing up in search (see below)
alt text

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...