Knowledge Management

How to enrich "index" field in any datamodel?

mdey
New Member

I have a data model where I want to enrich "index" field. I m very new to datamodel section and reading docs to gain some knowledge. Any sort of help or reference will be appreciated.

Thanks & Regards.

Tags (1)
0 Karma

mayurr98
Super Champion

go to datamodel>create_new>add dataset>root event>constraints and in constraints write index=<your_index>

this is how you can enrich a specific index in a data model.

If this does not answer your question, then can you please be specific about what do you want?

Let me know if you need any help!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...