<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting alias for multivalued field for ES/CIM compliance in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-alias-for-multivalued-field-for-ES-CIM-compliance/m-p/438597#M5831</link>
    <description>&lt;P&gt;I created an alias for the X_MS_Forwarded_Client_IP (ADFS events) to equal to src. The X_MS_Forwarded_Client_IP is a multivalue field which leads me to a few questions:&lt;/P&gt;

&lt;P&gt;1) We are running ES so do I need to do anything further to ensure that the new src field for the ADFS logs is included in the data model and CIM compliant? The app I created the initial alias was under Search &amp;amp; Reporting (search). Should this alias be under a different app, or does creating an alias and setting permission to all apps satisfy that requirement?&lt;/P&gt;

&lt;P&gt;2) Do I need to make any additional config changes due to the field being multivalued? Right now for searches, I add &lt;CODE&gt;| makemv delim="," src&lt;/CODE&gt; at the end to break them out. I worry with ES data models/CIM so additional configuration might need to be made to break them out automatically&lt;/P&gt;

&lt;P&gt;Thx&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 00:20:39 GMT</pubDate>
    <dc:creator>jwalzerpitt</dc:creator>
    <dc:date>2020-09-30T00:20:39Z</dc:date>
    <item>
      <title>Setting alias for multivalued field for ES/CIM compliance</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-alias-for-multivalued-field-for-ES-CIM-compliance/m-p/438597#M5831</link>
      <description>&lt;P&gt;I created an alias for the X_MS_Forwarded_Client_IP (ADFS events) to equal to src. The X_MS_Forwarded_Client_IP is a multivalue field which leads me to a few questions:&lt;/P&gt;

&lt;P&gt;1) We are running ES so do I need to do anything further to ensure that the new src field for the ADFS logs is included in the data model and CIM compliant? The app I created the initial alias was under Search &amp;amp; Reporting (search). Should this alias be under a different app, or does creating an alias and setting permission to all apps satisfy that requirement?&lt;/P&gt;

&lt;P&gt;2) Do I need to make any additional config changes due to the field being multivalued? Right now for searches, I add &lt;CODE&gt;| makemv delim="," src&lt;/CODE&gt; at the end to break them out. I worry with ES data models/CIM so additional configuration might need to be made to break them out automatically&lt;/P&gt;

&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:20:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-alias-for-multivalued-field-for-ES-CIM-compliance/m-p/438597#M5831</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2020-09-30T00:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: Setting alias for multivalued field for ES/CIM compliance</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-alias-for-multivalued-field-for-ES-CIM-compliance/m-p/438598#M5832</link>
      <description>&lt;P&gt;If your sourcetype/index is already included in the datamodel for your use cases, it will automatically pick the 'src' field as per the datamodel. If you don't want the values to be MV, you can convert to single values using fields.conf - TOKENIZER. &lt;/P&gt;

&lt;P&gt;Its generally a good practice to have your changes in a custom app or one of the existing app and not in search and reporting. If you want your knowledge objects to be visible for other apps, yes, it should be global permission. [ you can also put all your changes in an app and setup export].&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 15:32:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-alias-for-multivalued-field-for-ES-CIM-compliance/m-p/438598#M5832</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-05-03T15:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Setting alias for multivalued field for ES/CIM compliance</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-alias-for-multivalued-field-for-ES-CIM-compliance/m-p/438599#M5833</link>
      <description>&lt;P&gt;Thx for the reply and information - greatly appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 17:00:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Setting-alias-for-multivalued-field-for-ES-CIM-compliance/m-p/438599#M5833</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2019-05-06T17:00:41Z</dc:date>
    </item>
  </channel>
</rss>

