All Apps and Add-ons

Where can I find a list of Splunk Common Information Model (CIM) fields?

HealyManTech
Explorer

Is there a CIM document that lists the fields for it? I looked in documents but they only really explain it and I haven't found a list of it.

1 Solution

rpille_splunk
Splunk Employee
Splunk Employee

The data model reference tables are linked in this table: http://docs.splunk.com/Documentation/CIM/4.11.0/User/Overview#What_data_models_are_included

Is that what you were looking for?

View solution in original post

tomasmoser
Contributor

A list of all CIM fields (with mapping to corresponding  data model they are used in) are available in CIM documentation since 4.15.0 version:

CIM App documentation -> Data Model -> CIM fields per associated data model

https://docs.splunk.com/Documentation/CIM/4.18.0/User/CIMfields

 

zonistj
Path Finder

Hello,

I see that you already accepted an answer, but I wanted to inform you of the CIM Validator app. It has a csv lookup table of all of the CIM fields and their data model mappings.

The original app is here:

https://github.com/hire-vladimir/SA-cim_vladiator

I forked it and updated the dictionary to be CIM 4.12.0 (current) compliant:

https://github.com/zoneice/SA-cim_vladiator

Here's a link directly to the csv if you aren't interested in the full app:

https://github.com/zoneice/SA-cim_vladiator/blob/master/lookups/cim_dictionary.csv

harsmarvania57
Ultra Champion

Hi,

Have you gone through this document http://docs.splunk.com/Documentation/CIM/4.11.0/User/Authentication ? This document is for Authentication datamodel but there are other pages available (Click next page) for other datamodels which shipped with CIM.

rpille_splunk
Splunk Employee
Splunk Employee

The data model reference tables are linked in this table: http://docs.splunk.com/Documentation/CIM/4.11.0/User/Overview#What_data_models_are_included

Is that what you were looking for?

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...