Splunk Cloud Platform

Splunk Cloud InfoSec App

djoherl
New Member

Hello All,

I'm receiving a warning from our InfoSec app that my data isn't CIM compliant.  We have FortiGate syslogs, Windows Domain Controller Security logs, and Carbon Black Cloud logs being sent to Splunk Cloud.  

As far as I can tell, the logs being sent are CIM-compliant.  Is there anything else I can check?  

Thanks, Doug

Labels (2)
0 Karma

bharathkumarnec
Contributor

@djoherl all the necessary add-ons for the onboarded logsources are installed? Health check dashboard will give some information to start with...

0 Karma
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...

Enterprise Security Content Update (ESCU) | New Releases

In March, the Splunk Threat Research Team had 2 releases of security content via the Enterprise Security ...

Join the Splunk Developer Program Hackathon: Splunk Build-a-thon!

The Splunk Developer Program is launching in beta, and we’re celebrating with an exciting hackathon! This is ...