Splunk Cloud Platform

Questions related to upload data

RaviThummala
Observer

Hi Team,

we have some questions on uploading data.

1) Can we upload sample json/csv data with CIM compatible, can we see any demo ?

2) how to ingest network / network-traffic related sample data on splunk enterprise ?

3) Similarly looking for some more sample data related to email or mac-addr etc on splunk enterprise (trial account).

Regards
Anand

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RaviThummala,

CIM compatibility isn't related to a format but to technologies, so you have to identify the Add-On for your technology and use it to test CIM compliance.

If you want some sample in json format or about network traffic, you can install the Splunk Security Essentials App (https://splunkbase.splunk.com/app/3435) that gives you many searches and also all the sample data.

Beware when you use a trial license becaus you can index only until 600 MB/day, otherwise, after three exceedings you will be in violation.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...