<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Common information model in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Common-information-model/m-p/172253#M3763</link>
    <description>&lt;P&gt;Common Information Model is an abstraction layer between Splunk data sources and Splunk apps (use cases, dashboards, analytics).&lt;BR /&gt;
In order to satisfy CIM mapping requirement, your data needs to be normalized, ie fields need to be aliased with CIM compliant names and &lt;STRONG&gt;your events need to be tagged to be associated with at least one model&lt;/STRONG&gt; on this list: &lt;A href="http://docs.splunk.com/Documentation/CIM/latest/User/Overview#What_data_models_are_included"&gt;http://docs.splunk.com/Documentation/CIM/latest/User/Overview#What_data_models_are_included&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Note: Creating your own data model will not get you CIM compliance.&lt;/STRONG&gt; &lt;/P&gt;</description>
    <pubDate>Mon, 17 Aug 2015 18:02:03 GMT</pubDate>
    <dc:creator>mreynov_splunk</dc:creator>
    <dc:date>2015-08-17T18:02:03Z</dc:date>
    <item>
      <title>Common information model</title>
      <link>https://community.splunk.com/t5/Reporting/Common-information-model/m-p/172250#M3760</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I developed splunk app and addon to monitor one infrastructure. While filling out app certification template, I found common information model term. Can anyone tell me what it is? How I should define this with respect to my app?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2015 12:31:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Common-information-model/m-p/172250#M3760</guid>
      <dc:creator>vikassanap2011</dc:creator>
      <dc:date>2015-08-17T12:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: Common information model</title>
      <link>https://community.splunk.com/t5/Reporting/Common-information-model/m-p/172251#M3761</link>
      <description>&lt;P&gt;The Common Information Model gives a common standard to Splunk data, so that an end-user does not have to know a specific fieldname in custom data. For example, &lt;CODE&gt;username&lt;/CODE&gt; is mapped to &lt;CODE&gt;user&lt;/CODE&gt; to be considered CIM compliant.&lt;/P&gt;

&lt;P&gt;Read the manual here: &lt;A href="http://docs.splunk.com/Documentation/CIM/4.2.0/User/Overview"&gt;http://docs.splunk.com/Documentation/CIM/4.2.0/User/Overview&lt;/A&gt;. This gives a great insight into this configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2015 13:02:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Common-information-model/m-p/172251#M3761</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-08-17T13:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Common information model</title>
      <link>https://community.splunk.com/t5/Reporting/Common-information-model/m-p/172252#M3762</link>
      <description>&lt;P&gt;Thanks!&lt;BR /&gt;
Now, my app is ready.&lt;BR /&gt;
Do i need to create a data model for it &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.4/PivotTutorial/Buildtutorialdatamodel"&gt;link text&lt;/A&gt;.&lt;BR /&gt;
Actually I am not getting what i need to change or add to satisfy app certification criteria of CIM.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2015 14:36:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Common-information-model/m-p/172252#M3762</guid>
      <dc:creator>vikassanap2011</dc:creator>
      <dc:date>2015-08-17T14:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Common information model</title>
      <link>https://community.splunk.com/t5/Reporting/Common-information-model/m-p/172253#M3763</link>
      <description>&lt;P&gt;Common Information Model is an abstraction layer between Splunk data sources and Splunk apps (use cases, dashboards, analytics).&lt;BR /&gt;
In order to satisfy CIM mapping requirement, your data needs to be normalized, ie fields need to be aliased with CIM compliant names and &lt;STRONG&gt;your events need to be tagged to be associated with at least one model&lt;/STRONG&gt; on this list: &lt;A href="http://docs.splunk.com/Documentation/CIM/latest/User/Overview#What_data_models_are_included"&gt;http://docs.splunk.com/Documentation/CIM/latest/User/Overview#What_data_models_are_included&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Note: Creating your own data model will not get you CIM compliance.&lt;/STRONG&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2015 18:02:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Common-information-model/m-p/172253#M3763</guid>
      <dc:creator>mreynov_splunk</dc:creator>
      <dc:date>2015-08-17T18:02:03Z</dc:date>
    </item>
  </channel>
</rss>

