Knowledge Management

Field Name Recommendation - CIM?

daniel333
Builder

We have a common field in our log to track user activity which we currently call "dye". We're in the process of changing this at this time. So I can name it what ever I want. Skimming CIM docs I don't see anything that jumps out at me.

Anyone in the know with CIM, have a recommendation for me? I feel like there should be a CIM field for sessionID or userjavasession or something like that. Any recommendations?

0 Karma

muebel
SplunkTrust
SplunkTrust

You can find the various Data Models utilized by the CIM here : http://docs.splunk.com/Documentation/CIM/latest/User/Web

The Web DM is in that link, but you can see the rest of them on the left hand side. It sounds like the Web DM might be what you're interested in, but let me know how it works out.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...