Splunk Enterprise Security

CIM compliance of data from two different sources

rajashekar_s
Path Finder

I have two set of questions on which I am looking for inputs.
1. I have data from multiple tables for an application. I have onboarded it using db connect (mssql). I have to map the login data in tables to authentication datamodel. For achieveing this i need data from 2 separate tables (sources) to be joined which will give me valid login information along with other fields required for authentication datamodel.
My question is, how do i implement CIM for a multi source data?
2. I would also be interested to understand how do I implement CIM compliance for date where I have to join 2 separate indexes. One way i thought was to use kv lookup for one index and make it automatic lookup for 2nd index and use the fields. This will make the lookup file too huge. Other way is to have a saved search and run it regularly to populate data from one index and use collect command to place it in second index. This again takes me to my first question as to how do i implement CIM for 2 sources in same index.

0 Karma

woodcock
Esteemed Legend

I am not sure that I get what you are saying but I think that you are saying that the full set of data is in 2 index values. In such a case I would mine the one that is pretty static and schedule a search that creates a lookup file out of it and then create an automatic lookup for the other sourcetype that merges the data. The only other option is to create a scheduled search that does a mashup of the data and dumps it back out merged with collect.

0 Karma

rajashekar_s
Path Finder

Yes. You got the problem correct. The issue is both indexes are very huge in data (win event viewer logs and db logs). So we will have a problem creating schedule search and doing auto lookup. We have tried it and its causing issues.
We have tested using collect to dump it to db index from winevent viewer index. So I have my data in two events now which again has to be merged to make it CIM compliant. This is where I am looking for some help.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...