Knowledge Management

Field Name Recommendation - CIM?


We have a common field in our log to track user activity which we currently call "dye". We're in the process of changing this at this time. So I can name it what ever I want. Skimming CIM docs I don't see anything that jumps out at me.

Anyone in the know with CIM, have a recommendation for me? I feel like there should be a CIM field for sessionID or userjavasession or something like that. Any recommendations?

0 Karma


You can find the various Data Models utilized by the CIM here :

The Web DM is in that link, but you can see the rest of them on the left hand side. It sounds like the Web DM might be what you're interested in, but let me know how it works out.

Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...