Hi,
I just wanted to ask if there are specific ways or cli commands to check if my log sources adhere to CIM?
I've checked the following link below but I need assistance outside of the CIM add-on. https://docs.splunk.com/Documentation/CIM/5.0.2/User/UsetheCIMtovalidateyourdata
Thank you in advance.
Mikhael
Hi @mohdmikhael,
you can find some apps is splunkbase that help you to verify the CIM compliance of your data sources.
I usually use the SA-CIM Validator App (https://splunkbase.splunk.com/app/2968) that says to me which fields are mandatory and eventually missed.
Ciao.
Giuseppe