All Apps and Add-ons

Vendor_region field missing from Change Data model in the CIM Add-on v4.17

moullos
Observer

Hi,

I am trying to implement some alerts relying on the "vendor_region" field in the "All_Changes" CIM dataset. The data model and relevant datasets are populated by AWS Cloudtrail logs pulled by the AWS add-on from an S3 bucket. 

While troubleshooting the search, I have noticed that despite the "vendor_region" field being listed in the documentation for CIM All_Changes dataset (I am using version 4.17) the field is not present in the data model in the actual CIM add-on.  Am I missing something?

Thanks

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

FWIW, that field is not present in CIM version 4.15 and I can't say that I've ever seen it.  Consider submitting feedback on the documentation page.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...