Knowledge Management

CIM data model for Azure activity logs in Splunk

bsanjee
Explorer

Hello,

I have onboarded activity logs from an azure subcription to splunk using Azure monitor addon for splunk, https://splunkbase.splunk.com/app/3534/#/details , and the logs are parsed into below sourcetypes,

amal:administrative
amal:serviceHealth
amal:resourceHealth
amal:security
amal:ascRecommendation
amal:ascAlert

Is there a CIM model for these sourcetypes? If not, how should CIM compliance be validated?

0 Karma

ssadh_splunk
Splunk Employee
Splunk Employee
0 Karma

HiroshiSatoh
Champion

This APP is not CIM compliant. You need to ask the creator, or associate yourself with CIM.
Good luck!

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...