Splunk Dev

Best CIM data Model for User Activities Data

manan_amin
Explorer

I'm trying to apply CIM model on User activity data. E.g. Session Activities,Process Activities,Network Activities

 

Which data model ( CIM ) best fit for this type of data ? 

 

P.S. I find Endpoint Data Model useful. is it correct data model ?

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
IMO, the events you describe are covered by separate data models. Authentication, Network Session, Endpoint, etc. Use the model that contains the events you need for the use case. It's possible to use more than one data model in a search.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Buttercup Games Tutorial Extension - part 9

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games Tutorial Extension - part 8

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Introducing the Splunk Developer Program!

Hey Splunk community! We are excited to announce that Splunk is launching the Splunk Developer Program in ...