Knowledge Management

Field Name Recommendation - CIM?

daniel333
Builder

We have a common field in our log to track user activity which we currently call "dye". We're in the process of changing this at this time. So I can name it what ever I want. Skimming CIM docs I don't see anything that jumps out at me.

Anyone in the know with CIM, have a recommendation for me? I feel like there should be a CIM field for sessionID or userjavasession or something like that. Any recommendations?

0 Karma

muebel
SplunkTrust
SplunkTrust

You can find the various Data Models utilized by the CIM here : http://docs.splunk.com/Documentation/CIM/latest/User/Web

The Web DM is in that link, but you can see the rest of them on the left hand side. It sounds like the Web DM might be what you're interested in, but let me know how it works out.

Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...