Hello there,
I would like to know what I´m doing wrong? I´m sending all logs sugested by the app but it seems something is wrong. Can anyone please help me to get this sorted?
Hi @wbueno2, as others pointed out, CIM compliant data is a must for the InfoSec app to work. Here is what you may want to do:
Hi @wbueno2, as others pointed out, CIM compliant data is a must for the InfoSec app to work. Here is what you may want to do:
Have you reviewed the setup requirements? Must be CIM compliant data with acceleration on required data models...
https://splunkbase.splunk.com/app/4240/#/details
How can I make sure the data is coming is CIM compliant? Apart from that I followed all the steps.
What are you expecting to see?
There´s no data coming to infosec.