<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIM and Physical Access Control Data Model - ES in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281655#M2312</link>
    <description>&lt;P&gt;You're right. The existing DMs should be good enough for now. Re-using saves a few CPU cycles and a lot of memory. If I come into a situation that requires its own model I'll let you know. There may be card reader specifics but that's not really my field so I can't think of a case that requires a DM on its own &lt;/P&gt;</description>
    <pubDate>Mon, 19 Sep 2016 17:41:33 GMT</pubDate>
    <dc:creator>mikaelbje</dc:creator>
    <dc:date>2016-09-19T17:41:33Z</dc:date>
    <item>
      <title>CIM and Physical Access Control Data Model - ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281653#M2310</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;are there any plans to add a Physical Access Control Data Model to the CIM? I'm considering putting physical access control logs (card readers, door openers etc) in ES and would like to know if this is planned. Otherwise I'll have to create my own DM.&lt;/P&gt;

&lt;P&gt;Perhaps the Authentication DM could be extended, or create a new one called Access?&lt;/P&gt;

&lt;P&gt;Anyone doing this already?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 10:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281653#M2310</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2016-09-19T10:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: CIM and Physical Access Control Data Model - ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281654#M2311</link>
      <description>&lt;P&gt;Hi Mikael,&lt;/P&gt;

&lt;P&gt;I'll start by asking what you need. There's two reasons for the information models: being able to find information, and being able to make high-speed, low-resolution decisions from the data. Examples:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I have twelve brands of card reader system and I want to look in the same field to find the friendly name of the protected location.&lt;/LI&gt;
&lt;LI&gt;I want to make a correlation search from accelerated fields that are specific to card readers.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I was trying to make up a card-reader specific correlation search that isn't just replication of an existing correlation search, but I'm not able to think of one. For instance, Brute Force or Impossible Access... tag the data as authentication and you're covered. Privilege escalation, tag the account management stuff... &lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 16:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281654#M2311</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2016-09-19T16:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: CIM and Physical Access Control Data Model - ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281655#M2312</link>
      <description>&lt;P&gt;You're right. The existing DMs should be good enough for now. Re-using saves a few CPU cycles and a lot of memory. If I come into a situation that requires its own model I'll let you know. There may be card reader specifics but that's not really my field so I can't think of a case that requires a DM on its own &lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 17:41:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281655#M2312</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2016-09-19T17:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: CIM and Physical Access Control Data Model - ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281656#M2313</link>
      <description>&lt;P&gt;We use Authentication Data Model, it makes it easy to correlate between door access and computer access. Just leverage the DVC or the SRC_host field to indicate the door name/id. &lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 21:49:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281656#M2313</guid>
      <dc:creator>mcronkrite_splu</dc:creator>
      <dc:date>2016-10-04T21:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: CIM and Physical Access Control Data Model - ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281657#M2314</link>
      <description>&lt;P&gt;Yep,I ended up doing this and prefixing the src field with "Door_". Now I just need to populate all the asset lists. Blah!&lt;/P&gt;

&lt;P&gt;If anyone is interested in seeing an example implementation, it's available here: &lt;A href="https://github.com/inspired/TA-Stanley-Access_Control"&gt;https://github.com/inspired/TA-Stanley-Access_Control&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 07:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-and-Physical-Access-Control-Data-Model-ES/m-p/281657#M2314</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2016-10-05T07:27:07Z</dc:date>
    </item>
  </channel>
</rss>

