All Apps and Add-ons

How to troubleshoot why SA-cim_validator is showing 0% compliance for data models that do have field values extracted properly?

responsys_cm
Builder

I'm using the Splunk CIM Validator app to validate that data is flowing into my Splunk Enterprise Security data models correctly. For a number of the data models, the app shows 0% compliance because there are no values extracted for any of the fields in the data model.

Yet when I run the search used by the data model, I see all of the fields that the CIM Validator is complaining about being extracted properly.

I have no idea how to troubleshoot this...

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

This may be permissions issue...
When you say "search used by the data model" - are you using the pivot feature?

0 Karma

responsys_cm
Builder

I'm logged in as the admin user. Take the Web data model -- (cim_Web_indexes) tag=web is the root level search. The cim_Web_indexes macro is: (index=cisco OR index=f5). If I run the CIM Validator using that search, it comes back with 48% compliant.

If I search on index=cisco tag=web, I get the exact same results. If I search on index=f5 tag=web, the CIM Validator finds zero events. But if I run that same search outside the CIM Validator app, I see results just fine.

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

CIM validator is stricter, I guess.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...