Knowledge Management

Malware_attacks dataset is not showing event under Malware Datamodel

rashid47010
Communicator

Dear Experts,

there are no events for "Malware"."Malware_attacks".

tags and eventtypes seems fine
but there are no events when I select
tag=malware in the search.

how can I troubleshoot Malware Datamodel issue.

Tags (1)
0 Karma
1 Solution

koshyk
Super Champion

Ok, there are few moving parts for displaying the tags

  1. Splunk CIM => https://docs.splunk.com/Documentation/CIM/4.13.0/User/Malware
  2. The Addon/TA which contains logic to extract the tags
  3. Your data/sourcetype

You need all of the above for the tag to show properly. So inorder to debug
a. Ensure your data/sourcetype contains malware type of events. Check if this sourcetype is used by the relevant Addon/TA
b. Go into the TA and check for props.conf, transforms.conf, eventtypes.conf & tags.conf. See if they are extracting properly from your data. Test this in DEV
c. If (a) and (b) is all good, then ensure your CIM app/addon is correct version.
d. Check for datamodels and its acceleration

View solution in original post

0 Karma

koshyk
Super Champion

Ok, there are few moving parts for displaying the tags

  1. Splunk CIM => https://docs.splunk.com/Documentation/CIM/4.13.0/User/Malware
  2. The Addon/TA which contains logic to extract the tags
  3. Your data/sourcetype

You need all of the above for the tag to show properly. So inorder to debug
a. Ensure your data/sourcetype contains malware type of events. Check if this sourcetype is used by the relevant Addon/TA
b. Go into the TA and check for props.conf, transforms.conf, eventtypes.conf & tags.conf. See if they are extracting properly from your data. Test this in DEV
c. If (a) and (b) is all good, then ensure your CIM app/addon is correct version.
d. Check for datamodels and its acceleration

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...