Splunk Enterprise Security

Difference between correlation search written with data modals and correlation search written with normal search query

VijaySrrie
Builder

Hi Team,

What is the difference between correlation search created with the datamodals and the correlation search created with normal search query.

Which is good to follow?

1 Solution

jkat54
SplunkTrust
SplunkTrust

Both are correlation searches that will ultimately produce notable events. What they search is completely up to you. Using a data model typically means the data you think the notable event occurs in, has been normalized to the model. Using regular indexed data can be slower on performance, but not necessarily. Imagine querying a very large data model versus a very small index, or even a small lookup table. One will be faster but both could be "enriched/normalized" with different fields.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Both are correlation searches that will ultimately produce notable events. What they search is completely up to you. Using a data model typically means the data you think the notable event occurs in, has been normalized to the model. Using regular indexed data can be slower on performance, but not necessarily. Imagine querying a very large data model versus a very small index, or even a small lookup table. One will be faster but both could be "enriched/normalized" with different fields.

Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...