<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Models CIM compliance how to indetify  data sources needed for the Data Sets individual fields in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-Models-CIM-compliance-how-to-indetify-data-sources-needed/m-p/660980#M111742</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240690"&gt;@DanAlexander&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the correct approach, in my opinion, is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;identify your Data Sources,&lt;/LI&gt;&lt;LI&gt;identify in Splunkbase the best Add-Ons for your Data Sources.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The CIM4.x compliant Add-Ons are ready to be used without any action.&lt;/P&gt;&lt;P&gt;If instead you have some data source without a CIM 4.x complaint Add-On, you have to create it using the Add-On Builder (&lt;A href="https://splunkbase.splunk.com/app/2962" target="_blank"&gt;https://splunkbase.splunk.com/app/2962&lt;/A&gt;) and the SA-CIM-Vladiator (&lt;A href="https://splunkbase.splunk.com/app/2968" target="_blank"&gt;https://splunkbase.splunk.com/app/2968&lt;/A&gt;) apps that guide you in this actions.&lt;/P&gt;&lt;P&gt;Following your example:&amp;nbsp;&lt;SPAN&gt;WinRegMon&amp;nbsp; belongs to the Splunk_TA_Windows Add-On that's CIM 4.x Compliant, so you don't need to perform any action.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2023 08:44:53 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-10-17T08:44:53Z</dc:date>
    <item>
      <title>Data Models CIM compliance how to indetify  data sources needed for the Data Sets individual fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Models-CIM-compliance-how-to-indetify-data-sources-needed/m-p/660979#M111741</link>
      <description>&lt;P&gt;Hi All, trying to identify what data source/sourcetype is needed for each individual field while performing Data Model CIM normalization. For example for Endpoint-&amp;gt;Ports/Data Set (&lt;A href="https://docs.splunk.com/Documentation/CIM/5.2.0/User/Endpoint" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/CIM/5.2.0/User/Endpoint&lt;/A&gt;) there is a table with 5 columns Dataset Name/Field name/Data type/Description/Abbreviated list of example values/, but there is no guidance of what data source is needed for each individual field to start populating. As an example, I recently found that for the Registry Data Set it needs WinRegMon stanza (configuring this is another challenge &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;) to be able to recognise and start parsing data. Any help much appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 08:23:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Models-CIM-compliance-how-to-indetify-data-sources-needed/m-p/660979#M111741</guid>
      <dc:creator>DanAlexander</dc:creator>
      <dc:date>2023-10-17T08:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: Data Models CIM compliance how to indetify  data sources needed for the Data Sets individual fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Models-CIM-compliance-how-to-indetify-data-sources-needed/m-p/660980#M111742</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240690"&gt;@DanAlexander&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the correct approach, in my opinion, is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;identify your Data Sources,&lt;/LI&gt;&lt;LI&gt;identify in Splunkbase the best Add-Ons for your Data Sources.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The CIM4.x compliant Add-Ons are ready to be used without any action.&lt;/P&gt;&lt;P&gt;If instead you have some data source without a CIM 4.x complaint Add-On, you have to create it using the Add-On Builder (&lt;A href="https://splunkbase.splunk.com/app/2962" target="_blank"&gt;https://splunkbase.splunk.com/app/2962&lt;/A&gt;) and the SA-CIM-Vladiator (&lt;A href="https://splunkbase.splunk.com/app/2968" target="_blank"&gt;https://splunkbase.splunk.com/app/2968&lt;/A&gt;) apps that guide you in this actions.&lt;/P&gt;&lt;P&gt;Following your example:&amp;nbsp;&lt;SPAN&gt;WinRegMon&amp;nbsp; belongs to the Splunk_TA_Windows Add-On that's CIM 4.x Compliant, so you don't need to perform any action.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 08:44:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Models-CIM-compliance-how-to-indetify-data-sources-needed/m-p/660980#M111742</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-17T08:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: Data Models CIM compliance how to indetify  data sources needed for the Data Sets individual fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Models-CIM-compliance-how-to-indetify-data-sources-needed/m-p/660985#M111744</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;thanks for your reply.&lt;/P&gt;&lt;P&gt;Agree with what you suggested. However, I found it challenging to recognize stanzas that can be used for completing each individual field. I am using Vladiator and filling in gaps that way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;From what you said "Following your example:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;WinRegMon&amp;nbsp; belongs to the Splunk_TA_Windows Add-On that's CIM 4.x Compliant, so you don't need to perform any action."&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WinRegMon was there but I had to discover it myself as all options that come under the default folder/inputs.conf are lots and they are disabled by default for the user to decide on which ones to enable and for what purpose. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would you be able to help me identify the best and appropriate way to decide on how to enable the Ports Data Set's fields (currently not getting any data in...is ti coming from SysMon or any other data sourcetype?) from the Endpoint Data Model?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hope you can understand my challenge.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 09:22:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Models-CIM-compliance-how-to-indetify-data-sources-needed/m-p/660985#M111744</guid>
      <dc:creator>DanAlexander</dc:creator>
      <dc:date>2023-10-17T09:22:25Z</dc:date>
    </item>
  </channel>
</rss>

