Splunk Search

Data Models query

mag85032
Engager

 

Can someone help with a query to identify any events which could align with existing Data models, that contain information like (Users,actions performed, session ids, etc), for specific source type and index.

Fields like Users, Actions Performed, Session id , do we need to extract, can someone help with the query?

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...