Differences between data models and saved searches
Data models and saved searches both let you organize data. However, there are a few differences.
Use a data model for the following use cases:
- To show hierarchy between your data sets
- To make data common across multiple datasets and devices
- To simplify complex datasets for end users
- When end user interaction is required
Use a saved search for the following use cases:
- To run scheduled reports
- When end user interaction is not required
About the Splunk Phantom Add-on for Splunk | Create a data model export to send data to Splunk Phantom |
This documentation applies to the following versions of Splunk® Phantom App for Splunk: 2.7.5, 3.0.5, 4.0.10, 4.0.35
Feedback submitted, thanks!