Knowledge Management

Writing our first custom App for Avecto chassis_type CIM model

jonxilinx
Explorer

Hi, Looking for some advice
We have an Asset field trying to get into CIM compliance

ChassisType =   Laptop, Notebook,Docking Station,Desktop,Server etc

What is the most appropriate field in the CIM Inventory event dataset to write this too?

We have other sources of inventory and would like to map for inventory type reports

0 Karma
1 Solution

micahkemp
Champion

I'm not sure that ChassisType, as you have detailed it in your question, maps to any of the CIM Inventory datamodel fields. I didn't see one that seemed to fit.

Keep in mind that when conforming to the CIM, you will almost certainly have fields in your events that don't correlate to CIM fields. This doesn't mean your data is wrong, or that the CIM is incomplete. Instead the CIM exists in order to provide a common set of fields that are used frequently enough to justify having a normalized name.

View solution in original post

0 Karma

mh2112
New Member

Hey there jonxilinx,

You most certainly could use a field alias to map ChassisType to an appropriate field in the Inventory data model. Maybe the vendor_product field? Totally depends on how robust your environment is, how this new addition could affect any other searches using the Inventory DM (your aforementioned inventory type report), and personal preference on labeling.

In case you have not seen these, here is a link to the CIM reference table documentation - https://docs.splunk.com/Documentation/CIM/4.12.0/User/ComputeInventory

0 Karma

micahkemp
Champion

I'm not sure that ChassisType, as you have detailed it in your question, maps to any of the CIM Inventory datamodel fields. I didn't see one that seemed to fit.

Keep in mind that when conforming to the CIM, you will almost certainly have fields in your events that don't correlate to CIM fields. This doesn't mean your data is wrong, or that the CIM is incomplete. Instead the CIM exists in order to provide a common set of fields that are used frequently enough to justify having a normalized name.

View solution in original post

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!