The Splunk CIM Add-on provides dozens of pre-built Data Models (e.g., Network Traffic, Authentication, Malware).
These models are structured hierarchically. Using `tstats`, we can query these accelerated models natively.
| tstats count from datamodel=Authentication where Authentication.action="success" by _time span=1h