All Apps and Add-ons

Which of the Splunk CIM data models apply to the Forescout CounterACT App?

bigtyma
Communicator

Is anyone the using Forescout CounterAct App? Can anyone tell me which which if any of the Splunk CIM data models apply?

http://docs.splunk.com/Documentation/CIM/3.0.2/User/RelationshipofCIMappstodata

Thank you,

martaBenedetti
Path Finder
0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, it's easiest to think in terms of event types first... the CIM is really built on "type of thing that happened" rather than "brand of thing it happened to".

Totally ignoring the fact that it's a NAC, for any network security device I imagine you'll want to model some events to:

  • Change Analysis -- people often forget this, so I put it first... wouldn't it be nice to get an alert when your network security device gets reconfigured? Especially if the good guys didn't do that reconfig?
  • Authentication -- ditto, I want to know when someone logs into the device. Especially with an administrator level of privilege. That might be good to cross-reference with the add-on for ServiceNow, and see if there's a ticket open against this device...
  • Inventory -- how many do we have and where are they?
  • Performance -- are they barely ticking over, or at their limits?

And since this is a NAC device:

  • I would put the NAC decisions under Change Analysis, tag=network, because you're tracking decisions and configurations that alter the rules of access.
  • If there are actual block and allow events getting logged (e.g. "foo tried to talk to bar and I said no because rule baz"), those would go under Network Traffic.
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...