Quantcast
Channel: Questions in topic: "datamodel"
Viewing all articles
Browse latest Browse all 226

Search a Splunk Enterpirse Security DataModel - problem with Wildcards

$
0
0
Im trying to limit my search down to just certain accounts from the the authentication Data Model but wildcards dont seem to limit the results as I'd normally expect when search a specific index instead of the DM. I've tried a few options which I'd have hoped would work, but it just returns ALL account names; | datamodel Authentication Authentication search | search Account_Name="abc*" | datamodel Authentication Authentication search | search Account_Name="*abc*" | datamodel Authentication Authentication search | search Account_Name=abc* | datamodel Authentication Authentication search | where like(Account_Name,"abc%") Is there a particular way you should use a wildcard within a DM search? Thanks.

Viewing all articles
Browse latest Browse all 226

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>