Splunk Enterprise

data model field extraction

khanlarloo
Explorer

Hi,I have a dns log whose fields are not extracted properly and so I used Rex.

I encountered a problem. When i search index = dns * source = "516" host = dns -sender All fields are extracted correctly.

But when i search

| "from datamodel:" Network_Resolution

| search dns -sender

My fields get value of unknown.

Can anyone help me !!!!

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @khanlarloo 

The fields extracted shall be normalized to fit into Data model that you are querying. You should have CIM app installed  to Splunk SH prior and you need to create at a highlevel eventtypes, tags and props for normalization. The process is not straight forward.

This link help you to achieve then if everything is successful you can query the data model (DM) however the field names would be different from you originally extracted.

Use the CIM to normalize data at search time - Splunk Documentation

---

An upvote would be appreciated if this reply helps and Accept the solution!

0 Karma

khanlarloo
Explorer

I did everything you said according to the link you sent, but there is still the same problem.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...