Knowledge Management

Pre-defined Data Models

rmck2012
New Member

Does anybody know if there are pre-defined or common data models that are documented somewhere that could be used as a guide to assist with building data models for those of us who are less familiar with that process?

For example, I would think there are numerous common data sources where a basic guide could be created to walk users who are new to Splunk 6 through the process of building a usable data model.

These common data sources could include things such as:

  • Cisco ASA logs
  • Microsoft domain controller security event logs
  • Web filter logs, such as from a Cisco Ironport or Barracuda web filter
  • Network infrastructure devices, such as Cisco switch and router logs

These are just a few, but it could be useful as a starting point to get users familiar with the process of creating and using data models in Splunk 6.

Thank you,

Rick

Tags (2)
0 Karma

araitz
Splunk Employee
Splunk Employee

Check out the Splunk Common Information Model app here:

http://apps.splunk.com/app/1621/

See the documentation here:

http://docs.splunk.com/Documentation/CIM/latest/User/RelationshipofCIMappstodata

Let us know what other data sources you would like to see data models for.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...