<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIM help in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-help/m-p/535073#M9609</link>
    <description>&lt;P&gt;Per documentation, for example the action field in network traffic datamodel, prescribed values are allowed, blocked and teardown. But you have many values under action field. As suggested above, you can create a calculated field like&lt;/P&gt;&lt;P&gt;| eval action=case((action="xxx" OR action="yyy"),"allowed",1=1,"blocked")&lt;/P&gt;&lt;P&gt;Doing this on all recommended fields will increase you compliance %&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jan 2021 16:31:07 GMT</pubDate>
    <dc:creator>rajashekar_s</dc:creator>
    <dc:date>2021-01-07T16:31:07Z</dc:date>
    <item>
      <title>CIM help</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-help/m-p/519538#M9261</link>
      <description>&lt;P&gt;I'm reviewing the logs to make sure the fields match the Splunk Enterprise Security CIM and datamodels.&lt;/P&gt;&lt;P&gt;The query shows me this percentage, understanding that they are the fields that are required versus the fields that it is finding, in this order of ideas, to adjust these fields I must create an alias or I must perform an "extract" either by regular expressions or tabs?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp_log.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10831iF9584B0F2E60C948/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp_log.png" alt="cp_log.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp_log2.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10832i885FC9191E90929C/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp_log2.png" alt="cp_log2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 18:17:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-help/m-p/519538#M9261</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2020-09-14T18:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: CIM help</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-help/m-p/519549#M9262</link>
      <description>&lt;P&gt;Yes, you need to extract fields or create aliases to increase your CIM compliance.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 19:26:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-help/m-p/519549#M9262</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-14T19:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: CIM help</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-help/m-p/535073#M9609</link>
      <description>&lt;P&gt;Per documentation, for example the action field in network traffic datamodel, prescribed values are allowed, blocked and teardown. But you have many values under action field. As suggested above, you can create a calculated field like&lt;/P&gt;&lt;P&gt;| eval action=case((action="xxx" OR action="yyy"),"allowed",1=1,"blocked")&lt;/P&gt;&lt;P&gt;Doing this on all recommended fields will increase you compliance %&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 16:31:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/CIM-help/m-p/535073#M9609</guid>
      <dc:creator>rajashekar_s</dc:creator>
      <dc:date>2021-01-07T16:31:07Z</dc:date>
    </item>
  </channel>
</rss>

