Knowledge Management

Field Name Recommendation - CIM?


We have a common field in our log to track user activity which we currently call "dye". We're in the process of changing this at this time. So I can name it what ever I want. Skimming CIM docs I don't see anything that jumps out at me.

Anyone in the know with CIM, have a recommendation for me? I feel like there should be a CIM field for sessionID or userjavasession or something like that. Any recommendations?

0 Karma


You can find the various Data Models utilized by the CIM here :

The Web DM is in that link, but you can see the rest of them on the left hand side. It sounds like the Web DM might be what you're interested in, but let me know how it works out.

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...