All Apps and Add-ons

Where can I find a list of Splunk Common Information Model (CIM) fields?

HealyManTech
Explorer

Is there a CIM document that lists the fields for it? I looked in documents but they only really explain it and I haven't found a list of it.

1 Solution

rpille_splunk
Splunk Employee
Splunk Employee

The data model reference tables are linked in this table: http://docs.splunk.com/Documentation/CIM/4.11.0/User/Overview#What_data_models_are_included

Is that what you were looking for?

View solution in original post

tomasmoser
Contributor

A list of all CIM fields (with mapping to corresponding  data model they are used in) are available in CIM documentation since 4.15.0 version:

CIM App documentation -> Data Model -> CIM fields per associated data model

https://docs.splunk.com/Documentation/CIM/4.18.0/User/CIMfields

 

zonistj
Path Finder

Hello,

I see that you already accepted an answer, but I wanted to inform you of the CIM Validator app. It has a csv lookup table of all of the CIM fields and their data model mappings.

The original app is here:

https://github.com/hire-vladimir/SA-cim_vladiator

I forked it and updated the dictionary to be CIM 4.12.0 (current) compliant:

https://github.com/zoneice/SA-cim_vladiator

Here's a link directly to the csv if you aren't interested in the full app:

https://github.com/zoneice/SA-cim_vladiator/blob/master/lookups/cim_dictionary.csv

harsmarvania57
Ultra Champion

Hi,

Have you gone through this document http://docs.splunk.com/Documentation/CIM/4.11.0/User/Authentication ? This document is for Authentication datamodel but there are other pages available (Click next page) for other datamodels which shipped with CIM.

rpille_splunk
Splunk Employee
Splunk Employee

The data model reference tables are linked in this table: http://docs.splunk.com/Documentation/CIM/4.11.0/User/Overview#What_data_models_are_included

Is that what you were looking for?

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...