- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Vendor_region field missing from Change Data model in the CIM Add-on v4.17
moullos
Observer
04-05-2021
05:18 AM
Hi,
I am trying to implement some alerts relying on the "vendor_region" field in the "All_Changes" CIM dataset. The data model and relevant datasets are populated by AWS Cloudtrail logs pulled by the AWS add-on from an S3 bucket.
While troubleshooting the search, I have noticed that despite the "vendor_region" field being listed in the documentation for CIM All_Changes dataset (I am using version 4.17) the field is not present in the data model in the actual CIM add-on. Am I missing something?
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
04-05-2021
08:56 AM
FWIW, that field is not present in CIM version 4.15 and I can't say that I've ever seen it. Consider submitting feedback on the documentation page.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
