- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello there,
I would like to know what I´m doing wrong? I´m sending all logs sugested by the app but it seems something is wrong. Can anyone please help me to get this sorted?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @wbueno2, as others pointed out, CIM compliant data is a must for the InfoSec app to work. Here is what you may want to do:
- Review the installation instructions for the InfoSec app
- Check whether you have the CIM add-on installed
- Accelerate the data models (Settings>Data Models) listed in the instructions
- Check whether you use CIM-compliant add-ons for your data. In your case, for example, you should have Cisco ASA and Windows add-ons installed on your Splunk server (or Search Heads in distributed environment). Check installation instructions for the add-ons.
- Go to InfoSec app > Health and Stats and check the following two tables:
- "Data Models Used by the InfoSec App: Events in Past 24 Hours"
- "All Data Models: Status" (You may need to wait from 5 minutes to an hour or more depending how much data you are sending to Splunk and how behind data models are on acceleration)
- If you see only red in the tables above, your data is not CIM compliant and/or data models are not accelerated. This is where you may want to look at these two resources:
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @wbueno2, as others pointed out, CIM compliant data is a must for the InfoSec app to work. Here is what you may want to do:
- Review the installation instructions for the InfoSec app
- Check whether you have the CIM add-on installed
- Accelerate the data models (Settings>Data Models) listed in the instructions
- Check whether you use CIM-compliant add-ons for your data. In your case, for example, you should have Cisco ASA and Windows add-ons installed on your Splunk server (or Search Heads in distributed environment). Check installation instructions for the add-ons.
- Go to InfoSec app > Health and Stats and check the following two tables:
- "Data Models Used by the InfoSec App: Events in Past 24 Hours"
- "All Data Models: Status" (You may need to wait from 5 minutes to an hour or more depending how much data you are sending to Splunk and how behind data models are on acceleration)
- If you see only red in the tables above, your data is not CIM compliant and/or data models are not accelerated. This is where you may want to look at these two resources:
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Have you reviewed the setup requirements? Must be CIM compliant data with acceleration on required data models...
https://splunkbase.splunk.com/app/4240/#/details
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How can I make sure the data is coming is CIM compliant? Apart from that I followed all the steps.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


What are you expecting to see?
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There´s no data coming to infosec.
