Knowledge Management

Is it possible to search against all datamodels for all available sourcetypes in a single query?

att35
Builder

Hi,

While tuning Splunk ES whenever there is a need to see if a datamodel can see required fields from a specific sourcetype, we use the following search

| datamodel Malware search | search sourcetype=<sourcetype>

sourcetype=* works but we still need to specify a datamodel. I was wondering if it is possible to search across all the Datamodels & All sourcetypes at once in a single query? If it is then maybe we can stats by datamodel, sourcetype to get a full picture.

Thanks,

~ Abhi

Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...