All Apps and Add-ons

Where can I find a list of Splunk Common Information Model (CIM) fields?

HealyManTech
Explorer

Is there a CIM document that lists the fields for it? I looked in documents but they only really explain it and I haven't found a list of it.

1 Solution

rpille_splunk
Splunk Employee
Splunk Employee

The data model reference tables are linked in this table: http://docs.splunk.com/Documentation/CIM/4.11.0/User/Overview#What_data_models_are_included

Is that what you were looking for?

View solution in original post

tomasmoser
Contributor

A list of all CIM fields (with mapping to corresponding  data model they are used in) are available in CIM documentation since 4.15.0 version:

CIM App documentation -> Data Model -> CIM fields per associated data model

https://docs.splunk.com/Documentation/CIM/4.18.0/User/CIMfields

 

zonistj
Path Finder

Hello,

I see that you already accepted an answer, but I wanted to inform you of the CIM Validator app. It has a csv lookup table of all of the CIM fields and their data model mappings.

The original app is here:

https://github.com/hire-vladimir/SA-cim_vladiator

I forked it and updated the dictionary to be CIM 4.12.0 (current) compliant:

https://github.com/zoneice/SA-cim_vladiator

Here's a link directly to the csv if you aren't interested in the full app:

https://github.com/zoneice/SA-cim_vladiator/blob/master/lookups/cim_dictionary.csv

harsmarvania57
Ultra Champion

Hi,

Have you gone through this document http://docs.splunk.com/Documentation/CIM/4.11.0/User/Authentication ? This document is for Authentication datamodel but there are other pages available (Click next page) for other datamodels which shipped with CIM.

rpille_splunk
Splunk Employee
Splunk Employee

The data model reference tables are linked in this table: http://docs.splunk.com/Documentation/CIM/4.11.0/User/Overview#What_data_models_are_included

Is that what you were looking for?

Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...