Knowledge Management

CIM data model for Azure activity logs in Splunk

bsanjee
Explorer

Hello,

I have onboarded activity logs from an azure subcription to splunk using Azure monitor addon for splunk, https://splunkbase.splunk.com/app/3534/#/details , and the logs are parsed into below sourcetypes,

amal:administrative
amal:serviceHealth
amal:resourceHealth
amal:security
amal:ascRecommendation
amal:ascAlert

Is there a CIM model for these sourcetypes? If not, how should CIM compliance be validated?

0 Karma

ssadh_splunk
Splunk Employee
Splunk Employee
0 Karma

HiroshiSatoh
Champion

This APP is not CIM compliant. You need to ask the creator, or associate yourself with CIM.
Good luck!

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...