<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIM for Software in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/CIM-for-Software/m-p/564432#M12950</link>
    <description>&lt;P&gt;Should the data model for endpoint be extended or should we create a new data model for software inventory.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.20.1/User/Endpoint" target="_blank"&gt;https://docs.splunk.com/Documentation/CIM/4.20.1/User/Endpoint&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We're thinking of adding a section:&amp;nbsp; Endpoint - Software&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Dataset name&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Field name&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Data type&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Description&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Abbreviated list of example values&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%"&gt;Software&lt;/TD&gt;&lt;TD width="20%"&gt;Software_Name&lt;/TD&gt;&lt;TD width="20%"&gt;String&lt;/TD&gt;&lt;TD width="20%"&gt;Name of the software&lt;/TD&gt;&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Software&lt;/TD&gt;&lt;TD&gt;Software_Version&lt;/TD&gt;&lt;TD&gt;String&lt;/TD&gt;&lt;TD&gt;Version of the software&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Software&lt;/TD&gt;&lt;TD&gt;Software_Alias&lt;/TD&gt;&lt;TD&gt;String&lt;/TD&gt;&lt;TD&gt;Software Normalization Name&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Software&lt;/TD&gt;&lt;TD&gt;Status&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;boolean&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;Tracking that software was remove or installed&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were able to build a common information model for RHEL &amp;amp; windows using the following fields for software_name, software_version,&amp;nbsp; dest.&amp;nbsp; We'd extended the to baseline inventory lookup to add desc, and ip.&lt;/P&gt;&lt;P&gt;Are we thinking correctly?&amp;nbsp; We're able to do software baseline, normalization, and detect changes using the other data model this way right?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Aug 2021 21:46:00 GMT</pubDate>
    <dc:creator>youngsuh</dc:creator>
    <dc:date>2021-08-23T21:46:00Z</dc:date>
    <item>
      <title>CIM for Software</title>
      <link>https://community.splunk.com/t5/Alerting/CIM-for-Software/m-p/539014#M10208</link>
      <description>&lt;P&gt;Is there CIM for Software?&amp;nbsp; I have different sources.&amp;nbsp; ePO, ACAS, Windows add-on, and NIX add-on.&amp;nbsp; Would like to using data model from CIM if possible?&lt;/P&gt;&lt;P&gt;Here are the CIM I've already look at:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.18.0/User/Endpoint" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/CIM/4.18.0/User/Endpoint&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Endpoint&lt;/P&gt;&lt;P&gt;Inventory&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application State&lt;/P&gt;&lt;P&gt;I've also searched Splunk Answers but, no quick results.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 19:01:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/CIM-for-Software/m-p/539014#M10208</guid>
      <dc:creator>youngsuh</dc:creator>
      <dc:date>2021-02-08T19:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: CIM for Software</title>
      <link>https://community.splunk.com/t5/Alerting/CIM-for-Software/m-p/541866#M10266</link>
      <description>&lt;P&gt;Hi! If you mean "software" as a field name that might be associated with a data model, then no, that is not currently a field name associated with a data model:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.18.0/User/CIMfields" target="_blank"&gt;https://docs.splunk.com/Documentation/CIM/4.18.0/User/CIMfields&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 23:59:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/CIM-for-Software/m-p/541866#M10266</guid>
      <dc:creator>lkutch_splunk</dc:creator>
      <dc:date>2021-03-01T23:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: CIM for Software</title>
      <link>https://community.splunk.com/t5/Alerting/CIM-for-Software/m-p/564432#M12950</link>
      <description>&lt;P&gt;Should the data model for endpoint be extended or should we create a new data model for software inventory.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.20.1/User/Endpoint" target="_blank"&gt;https://docs.splunk.com/Documentation/CIM/4.20.1/User/Endpoint&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We're thinking of adding a section:&amp;nbsp; Endpoint - Software&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Dataset name&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Field name&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Data type&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Description&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;SPAN&gt;Abbreviated list of example values&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%"&gt;Software&lt;/TD&gt;&lt;TD width="20%"&gt;Software_Name&lt;/TD&gt;&lt;TD width="20%"&gt;String&lt;/TD&gt;&lt;TD width="20%"&gt;Name of the software&lt;/TD&gt;&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Software&lt;/TD&gt;&lt;TD&gt;Software_Version&lt;/TD&gt;&lt;TD&gt;String&lt;/TD&gt;&lt;TD&gt;Version of the software&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Software&lt;/TD&gt;&lt;TD&gt;Software_Alias&lt;/TD&gt;&lt;TD&gt;String&lt;/TD&gt;&lt;TD&gt;Software Normalization Name&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Software&lt;/TD&gt;&lt;TD&gt;Status&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;boolean&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;Tracking that software was remove or installed&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were able to build a common information model for RHEL &amp;amp; windows using the following fields for software_name, software_version,&amp;nbsp; dest.&amp;nbsp; We'd extended the to baseline inventory lookup to add desc, and ip.&lt;/P&gt;&lt;P&gt;Are we thinking correctly?&amp;nbsp; We're able to do software baseline, normalization, and detect changes using the other data model this way right?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 21:46:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/CIM-for-Software/m-p/564432#M12950</guid>
      <dc:creator>youngsuh</dc:creator>
      <dc:date>2021-08-23T21:46:00Z</dc:date>
    </item>
  </channel>
</rss>

