<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to validate data which is uploaded to Splunk is as per CIM model in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232987#M99028</link>
    <description>&lt;P&gt;Yes, I went through CIM Validation datamodel but I am not able to make much out of it.&lt;BR /&gt;
Could you please try to explain with example?&lt;/P&gt;</description>
    <pubDate>Wed, 25 May 2016 08:55:10 GMT</pubDate>
    <dc:creator>rupeshhiremath</dc:creator>
    <dc:date>2016-05-25T08:55:10Z</dc:date>
    <item>
      <title>How to validate data which is uploaded to Splunk is as per CIM model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232983#M99024</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;In our application we have data in a specific format. We are converting this data to CIM model (say IntrusionDetection, Malware etc) and then uploading to Splunk.&lt;BR /&gt;
Now once its get uploaded I want to verify from Splunk side whether that data is as per specific CIM model or not. &lt;BR /&gt;
How to go ahead with this?&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2016 07:38:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232983#M99024</guid>
      <dc:creator>rupeshhiremath</dc:creator>
      <dc:date>2016-05-06T07:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to validate data which is uploaded to Splunk is as per CIM model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232984#M99025</link>
      <description>&lt;P&gt;One useful thing is the &lt;A href="http://docs.splunk.com/Documentation/CIM/4.4.0/User/UsetheCIMtovalidateyourdata#Use_the_CIM_Validation_.28S.o.S..29_datamodel"&gt;CIM Validation datamodel&lt;/A&gt;.  This can help to find what extractions are still missing or which are misnamed.  You can install the CIM on a new test Splunk instance and feed a bit of the data to it and test, or if you are already pumping that data into your regular Splunk install, well, that's OK too.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I've also found usefulness from just cracking open the appropriate datamodel and doing some pivots.  A lot can be determined if you have a reasonably well known set of data and run some confirming pivots on that data.  &lt;/P&gt;</description>
      <pubDate>Sun, 08 May 2016 02:00:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232984#M99025</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-05-08T02:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to validate data which is uploaded to Splunk is as per CIM model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232985#M99026</link>
      <description>&lt;P&gt;Hi rich7177,&lt;/P&gt;

&lt;P&gt;Could you please elaborate more on this as I am new to Splunk. And more importantly I wanted to this with automation.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2016 11:45:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232985#M99026</guid>
      <dc:creator>rupeshhiremath</dc:creator>
      <dc:date>2016-05-09T11:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to validate data which is uploaded to Splunk is as per CIM model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232986#M99027</link>
      <description>&lt;P&gt;Rupeshshiremath, did you try reviewing the link to the CIM Validation datamodel that Rich posted? &lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2016 14:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232986#M99027</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2016-05-09T14:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to validate data which is uploaded to Splunk is as per CIM model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232987#M99028</link>
      <description>&lt;P&gt;Yes, I went through CIM Validation datamodel but I am not able to make much out of it.&lt;BR /&gt;
Could you please try to explain with example?&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 08:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232987#M99028</guid>
      <dc:creator>rupeshhiremath</dc:creator>
      <dc:date>2016-05-25T08:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to validate data which is uploaded to Splunk is as per CIM model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232988#M99029</link>
      <description>&lt;P&gt;And more importantly there is no directory called $SPLUNK_HOME/etc/apps/Splunk_SA_CIM/default&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:47:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232988#M99029</guid>
      <dc:creator>rupeshhiremath</dc:creator>
      <dc:date>2020-09-29T09:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to validate data which is uploaded to Splunk is as per CIM model</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232989#M99030</link>
      <description>&lt;P&gt;My bad..I was looking at different Splunk instance &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;
I am able to see missing extractions using CIM Validation datamodel..thank you.&lt;/P&gt;

&lt;P&gt;Now trying how can I use CIM Validation datamodel with python.&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2016 13:07:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-validate-data-which-is-uploaded-to-Splunk-is-as-per-CIM/m-p/232989#M99030</guid>
      <dc:creator>rupeshhiremath</dc:creator>
      <dc:date>2016-05-29T13:07:23Z</dc:date>
    </item>
  </channel>
</rss>

