Is Splunk Cisco ISE app and Splunk Cisco ISE Add-on already map to Splunk CIM by default? If not, is there any documentation that we can use to map it and be CIM compliant?
Yes, the SplunkBase site is showing combatibility to CIM Version 4.x
https://splunkbase.splunk.com/app/1915