sourcetype-fields

Document field names, types, and values for FAKE sourcetypes in the fake_tshrt Splunk index.

4|Updated Feb 7, 2026
One-click install
npx skills add https://github.com/lyderhansen/The-Fake-T-Shirt-Company --skill sourcetype-fields
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sourcetype-fields
Source: https://github.com/lyderhansen/The-Fake-T-Shirt-Company/tree/main/.claude/skills/sourcetype-fields
Command: npx skills add https://github.com/lyderhansen/The-Fake-T-Shirt-Company --skill sourcetype-fields

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a comprehensive reference for all fields across various sourcetypes within the fake_tshrt Splunk index, enabling users to effectively query and analyze the data.

Core Features & Use Cases

  • Field Inventory: Detailed listing of fields for each sourcetype, including data type, distinct values, and common values.
  • Data Model Understanding: Helps users grasp the structure and content of the synthetic data generated by The Fake T-Shirt Company.
  • SPL Query Optimization: Essential for writing accurate and efficient Splunk Processing Language (SPL) queries, building dashboards, and troubleshooting data issues.
  • Use Case: When investigating a network security event, quickly look up the available fields for FAKE:cisco:asa to identify source IP, destination port, and action taken.

Quick Start

Provide a detailed field breakdown for the FAKE:azure:aad:signin sourcetype.

Frequently Asked Questions about sourcetype-fields

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What fields are available for Splunk sourcetypes in the fake_tshrt index?

The fake_tshrt Splunk index contains network, cloud, collaboration, email, Windows, and Linux sourcetypes. Available fields include data types, distinct values, and common values to facilitate data analysis and SPL query writing.

How do I find field names and types for a specific Splunk sourcetype?

To find field names and types for a specific Splunk sourcetype, request a detailed field breakdown for that sourcetype. The reference provides field names, data types, distinct values, and common values for sources like FAKE:azure:aad:signin.

How do I handle dotted field names in Splunk SPL queries?

Dotted field names in Splunk SPL queries require specific quoting syntax to parse correctly. The field reference includes guidance on properly quoting dotted field names to ensure accurate data extraction and query execution.

Can I use this data dictionary to build Splunk dashboards for network security events?

Yes, this data dictionary supports Splunk dashboard development for network security events. You can look up available fields for sourcetypes like FAKE:cisco:asa to identify source IP, destination port, and action taken for investigations.

Does the fake_tshrt index include cloud and collaboration data sources?

Yes, the fake_tshrt index includes cloud and collaboration data sources. The field reference covers multiple categories including cloud, collaboration, email, Windows, and Linux data sourced from The Fake T-Shirt Company synthetic data.

What is the best way to write accurate SPL queries using synthetic Splunk data?

The best way to write accurate SPL queries using synthetic Splunk data is to consult a comprehensive field reference. This ensures you use correct field names, understand data types, and apply proper quoting for dotted fields.