Splunk® Phantom App for Splunk

Use the Splunk Phantom App for Splunk to Forward Events

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® Phantom App for Splunk. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Differences between data models and saved searches

Data models and saved searches both let you organize data. However, there are a few differences.

Use a data model for the following use cases:

  • To show hierarchy between your data sets
  • To make data common across multiple datasets and devices
  • To simplify complex datasets for end users
  • When end user interaction is required

Use a saved search for the following use cases:

  • To run scheduled reports
  • When end user interaction is not required
Last modified on 11 August, 2020
PREVIOUS
About the Splunk Phantom Add-on for Splunk
  NEXT
Create a data model export to send data to Splunk Phantom

This documentation applies to the following versions of Splunk® Phantom App for Splunk: 2.7.5, 3.0.5, 4.0.10, 4.0.35


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters