Splunk Enterprise

data model field extraction

khanlarloo
Explorer

Hi,I have a dns log whose fields are not extracted properly and so I used Rex.

I encountered a problem. When i search index = dns * source = "516" host = dns -sender All fields are extracted correctly.

But when i search

| "from datamodel:" Network_Resolution

| search dns -sender

My fields get value of unknown.

Can anyone help me !!!!

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @khanlarloo 

The fields extracted shall be normalized to fit into Data model that you are querying. You should have CIM app installed  to Splunk SH prior and you need to create at a highlevel eventtypes, tags and props for normalization. The process is not straight forward.

This link help you to achieve then if everything is successful you can query the data model (DM) however the field names would be different from you originally extracted.

Use the CIM to normalize data at search time - Splunk Documentation

---

An upvote would be appreciated if this reply helps and Accept the solution!

0 Karma

khanlarloo
Explorer

I did everything you said according to the link you sent, but there is still the same problem.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...