<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best CIM data Model for User Activities Data in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Best-CIM-data-Model-for-User-Activities-Data/m-p/508321#M9082</link>
    <description>&lt;P&gt;I'm trying to apply CIM model on User activity data. E.g.&amp;nbsp;Session Activities,Process Activities,Network Activities&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which data model ( CIM ) best fit for this type of data ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. I find Endpoint Data Model useful. is it correct data model ?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jul 2020 14:32:43 GMT</pubDate>
    <dc:creator>manan_amin</dc:creator>
    <dc:date>2020-07-09T14:32:43Z</dc:date>
    <item>
      <title>Best CIM data Model for User Activities Data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Best-CIM-data-Model-for-User-Activities-Data/m-p/508321#M9082</link>
      <description>&lt;P&gt;I'm trying to apply CIM model on User activity data. E.g.&amp;nbsp;Session Activities,Process Activities,Network Activities&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which data model ( CIM ) best fit for this type of data ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. I find Endpoint Data Model useful. is it correct data model ?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 14:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Best-CIM-data-Model-for-User-Activities-Data/m-p/508321#M9082</guid>
      <dc:creator>manan_amin</dc:creator>
      <dc:date>2020-07-09T14:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Best CIM data Model for User Activities Data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Best-CIM-data-Model-for-User-Activities-Data/m-p/508350#M9083</link>
      <description>IMO, the events you describe are covered by separate data models. Authentication, Network Session, Endpoint, etc. Use the model that contains the events you need for the use case. It's possible to use more than one data model in a search.</description>
      <pubDate>Thu, 09 Jul 2020 16:52:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Best-CIM-data-Model-for-User-Activities-Data/m-p/508350#M9083</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-09T16:52:58Z</dc:date>
    </item>
  </channel>
</rss>

