Hi All,
Has anyone managed to map CrowdStrike Falcon FileVantage (FIM) logs to a Datamodel; if so could you share your field mappings? We were looking at he Change DM, would this be the best option?
thanks
Hi @becksyboy ,
yes probably the Change DM is the best fit, but probably also the Authentication DM is useful, it depends on your Use Cases.
Ciao.
Giuseppe
hi @becksyboy ,
are you using the CrowdStrike Falcon FileVantage Technical Add-On ( https://splunkbase.splunk.com/app/7090 )?
if yes, this add-on should be already CIM compliant, but it isn.t true because in the add-on there isn't tags.conf and eventtypes.conf.
Anyway, I usually use to normalize data the SA-CIM_vladiator app ( https://splunkbase.splunk.com/app/2968 ) , that guides you in the normalization activity.
Ciao.
Giuseppe
Hi @gcusello yep we noticed the TA did not do CIM mapping 😶
In terms of FIM monitoring would you say the Change DM is the best fit, seems like it to me.
Hi @becksyboy ,
yes probably the Change DM is the best fit, but probably also the Authentication DM is useful, it depends on your Use Cases.
Ciao.
Giuseppe