Hi,
While tuning Splunk ES whenever there is a need to see if a datamodel can see required fields from a specific sourcetype, we use the following search
| datamodel Malware search | search sourcetype=<sourcetype>
sourcetype=*
works but we still need to specify a datamodel. I was wondering if it is possible to search across all the Datamodels & All sourcetypes at once in a single query? If it is then maybe we can stats
by datamodel, sourcetype to get a full picture.
Thanks,
~ Abhi