Knowledge Management

Writing our first custom App for Avecto chassis_type CIM model

jonxilinx
Path Finder

Hi, Looking for some advice
We have an Asset field trying to get into CIM compliance

ChassisType =   Laptop, Notebook,Docking Station,Desktop,Server etc

What is the most appropriate field in the CIM Inventory event dataset to write this too?

We have other sources of inventory and would like to map for inventory type reports

0 Karma
1 Solution

micahkemp
Champion

I'm not sure that ChassisType, as you have detailed it in your question, maps to any of the CIM Inventory datamodel fields. I didn't see one that seemed to fit.

Keep in mind that when conforming to the CIM, you will almost certainly have fields in your events that don't correlate to CIM fields. This doesn't mean your data is wrong, or that the CIM is incomplete. Instead the CIM exists in order to provide a common set of fields that are used frequently enough to justify having a normalized name.

View solution in original post

0 Karma

mh2112
New Member

Hey there jonxilinx,

You most certainly could use a field alias to map ChassisType to an appropriate field in the Inventory data model. Maybe the vendor_product field? Totally depends on how robust your environment is, how this new addition could affect any other searches using the Inventory DM (your aforementioned inventory type report), and personal preference on labeling.

In case you have not seen these, here is a link to the CIM reference table documentation - https://docs.splunk.com/Documentation/CIM/4.12.0/User/ComputeInventory

0 Karma

micahkemp
Champion

I'm not sure that ChassisType, as you have detailed it in your question, maps to any of the CIM Inventory datamodel fields. I didn't see one that seemed to fit.

Keep in mind that when conforming to the CIM, you will almost certainly have fields in your events that don't correlate to CIM fields. This doesn't mean your data is wrong, or that the CIM is incomplete. Instead the CIM exists in order to provide a common set of fields that are used frequently enough to justify having a normalized name.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...