All Apps and Add-ons

Splunk CIM Add-on 4.2.0: The docs state the Web object should be tagged by "WEB", but why is the Web root constrained with sourcetype=iis* in the data model?

kundeng
Path Finder

In the 4.2.0 version of the Common Information Model Add-on Manual, it states clearly the Web object name should be tagged by "web". However, in the actual data model downloaded from splunkbase, the Web root is constrained with sourcetype=iis*. Is this a bug or am I missing something?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

I think you must be seeing some locally applied constraint -- there's nothing like that out of the box.

dflodstrom
Builder

Where do you see the constraint 'sourcetype=iis*'.

I am using the latest version of CIM and my top level constraint is 'tag=web'.

0 Karma

kundeng
Path Finder

That is strange. I have the latest version which is Version 4.2.0.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...