1.

Does The App Have A Data Model?

Answer»

Yes! In Splunk 6.x, the data model feature allows Splunk users to QUICKLY visualize and analyze data with a point-and-click interface (INSTEAD of the Splunk search BAR language). This capability requires that the data be modeled into a Splunk Data Model which is a highly accelerated summary index of the data. Not only is there a data model for all Palo Alto Networks logs, all the app’s dashboards are based on this accelerated data model for extremely FAST data retrieval and visualization. So the app itself is using the same Data Model that Splunk administrators would use to generate visualizations.

Yes! In Splunk 6.x, the data model feature allows Splunk users to quickly visualize and analyze data with a point-and-click interface (instead of the Splunk search bar language). This capability requires that the data be modeled into a Splunk Data Model which is a highly accelerated summary index of the data. Not only is there a data model for all Palo Alto Networks logs, all the app’s dashboards are based on this accelerated data model for extremely fast data retrieval and visualization. So the app itself is using the same Data Model that Splunk administrators would use to generate visualizations.



Discussion

No Comment Found