Splunk Enterprise

data model field extraction

khanlarloo
Explorer

Hi,I have a dns log whose fields are not extracted properly and so I used Rex.

I encountered a problem. When i search index = dns * source = "516" host = dns -sender All fields are extracted correctly.

But when i search

| "from datamodel:" Network_Resolution

| search dns -sender

My fields get value of unknown.

Can anyone help me !!!!

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @khanlarloo 

The fields extracted shall be normalized to fit into Data model that you are querying. You should have CIM app installed  to Splunk SH prior and you need to create at a highlevel eventtypes, tags and props for normalization. The process is not straight forward.

This link help you to achieve then if everything is successful you can query the data model (DM) however the field names would be different from you originally extracted.

Use the CIM to normalize data at search time - Splunk Documentation

---

An upvote would be appreciated if this reply helps and Accept the solution!

0 Karma

khanlarloo
Explorer

I did everything you said according to the link you sent, but there is still the same problem.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...