All Apps and Add-ons

How to troubleshoot why SA-cim_validator is showing 0% compliance for data models that do have field values extracted properly?

responsys_cm
Builder

I'm using the Splunk CIM Validator app to validate that data is flowing into my Splunk Enterprise Security data models correctly. For a number of the data models, the app shows 0% compliance because there are no values extracted for any of the fields in the data model.

Yet when I run the search used by the data model, I see all of the fields that the CIM Validator is complaining about being extracted properly.

I have no idea how to troubleshoot this...

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

This may be permissions issue...
When you say "search used by the data model" - are you using the pivot feature?

0 Karma

responsys_cm
Builder

I'm logged in as the admin user. Take the Web data model -- (cim_Web_indexes) tag=web is the root level search. The cim_Web_indexes macro is: (index=cisco OR index=f5). If I run the CIM Validator using that search, it comes back with 48% compliant.

If I search on index=cisco tag=web, I get the exact same results. If I search on index=f5 tag=web, the CIM Validator finds zero events. But if I run that same search outside the CIM Validator app, I see results just fine.

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

CIM validator is stricter, I guess.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...