...ime By Status' that when I send to a search returns values other than HTTP status codes (200, 401, etc).
I do a pivot of the web datamodel and select 'status' and 'sourcetype' and I see the p...
...he datamodel The problem we have is that when we enter a new user in the loockup, if the datamodel is accelerated, it never updates the information for this new user, if we do not accelerate the data...
Hello,
I was curious to see if there are any best practices for mapping to CIM datamodels. More specifically, I'm looking for some guidelines on when (not) to map a certain field to a datamodel....
...owtousethesereferencetables , I open "Settings: (Knowledge) Datamodels" (the DataModel Editor) and then click on the JVM datamodel. I get a nasty 404 error:
404 Not Found
[Return to Splunk home p...
Hi,
I'm sure a similar Quest has already been posted - but I can't find anything regarding my exact problem.
However, I'm using a DataModel to unify about 30 sourcetypes with kinda-similar data...
Hello,
I have a question about modification of datamodel in CIM:
I would like to add one child dataset to DM "Change". Can I do it by separate application?
What I mean exactly: If I create a m...
I have an environment with a large number of sourcetypes and would like to map those to the appropriate CIM datamodel. While I generally know about the Splunk commands pivot and datamodel, their u...
I'm trying to extract data into a DataModel Attribute Regex. The data I'm trying to extract from the events get logged in a couple of ways. I've been at this a while trying to just extract the data...
...ourcetypes predefined and ready to go with eventtypes and tags so they work with Common Information ModelDataModels immediately (AWS TA for example). I'm not seeing anything like that for access_combined. A...