Using the Common Information Model Flashcards
What is the Common Information Model used for?
CIM provides a methodology for normalizing values to a common field name.
Splunk ES relies heavily on CIM compliant data when:
- Searching Data
- Running Reports
- Creating Dashboards
What are the steps necessary to use CIM with your data?
- Getting Data In
- Examine Data
- Tag Events
- Verify Tags
- Normalize Fields
- Validate Against Model
- Package as Add-on
What happens if your data does not have tags required by the CIM data model?
You won’t be able to run a pivot (the pivot will return 0 events).
What data models are included within the Splunk CIM Add-On?
Alerts
Authentication
Certificates
Change
Data Access
Databases
Data Loss Prevention
Email
Endpoint
Event Signatures
Interprocess Messaging
Intrusion Detection
Inventory
Java Virtual Machines (JVM)
Malware
Network Resolution (DNS)
Network Sessions
Network Traffic
Performance
Splunk Audit Logs
Ticket Management
Updates
Vulnerabilities
Web
By default, how is acceleration configured in the Splunk CIM add-on?
Turned off.
Which Knowledge Objet does Splunk CIM use to normalize data?
- Field Aliases
- Event Types
- Tags
- Field Extractions
- Lookups