Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I search using a data model?

$
0
0
I've been working on a report that shows the dropped or blocked traffic using the interesting ports lookup table. I want to change this to search the network data model so I'm not using the "*" for my index. Any help on this would be great. Thanks. index=* action="blocked" OR action="dropped" [| inputlookup interesting_ports_lookup | fields dest_port] | table dest_port, dest_ip, src, app

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>