All Apps and Add-ons

Splunk CIM Add-on 4.2.0: The docs state the Web object should be tagged by "WEB", but why is the Web root constrained with sourcetype=iis* in the data model?

kundeng
Path Finder

In the 4.2.0 version of the Common Information Model Add-on Manual, it states clearly the Web object name should be tagged by "web". However, in the actual data model downloaded from splunkbase, the Web root is constrained with sourcetype=iis*. Is this a bug or am I missing something?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

I think you must be seeing some locally applied constraint -- there's nothing like that out of the box.

dflodstrom
Builder

Where do you see the constraint 'sourcetype=iis*'.

I am using the latest version of CIM and my top level constraint is 'tag=web'.

0 Karma

kundeng
Path Finder

That is strange. I have the latest version which is Version 4.2.0.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...