Splunk Enterprise Security

CIM compliance of data from two different sources

rajashekar_s
Path Finder

I have two set of questions on which I am looking for inputs.
1. I have data from multiple tables for an application. I have onboarded it using db connect (mssql). I have to map the login data in tables to authentication datamodel. For achieveing this i need data from 2 separate tables (sources) to be joined which will give me valid login information along with other fields required for authentication datamodel.
My question is, how do i implement CIM for a multi source data?
2. I would also be interested to understand how do I implement CIM compliance for date where I have to join 2 separate indexes. One way i thought was to use kv lookup for one index and make it automatic lookup for 2nd index and use the fields. This will make the lookup file too huge. Other way is to have a saved search and run it regularly to populate data from one index and use collect command to place it in second index. This again takes me to my first question as to how do i implement CIM for 2 sources in same index.

0 Karma

woodcock
Esteemed Legend

I am not sure that I get what you are saying but I think that you are saying that the full set of data is in 2 index values. In such a case I would mine the one that is pretty static and schedule a search that creates a lookup file out of it and then create an automatic lookup for the other sourcetype that merges the data. The only other option is to create a scheduled search that does a mashup of the data and dumps it back out merged with collect.

0 Karma

rajashekar_s
Path Finder

Yes. You got the problem correct. The issue is both indexes are very huge in data (win event viewer logs and db logs). So we will have a problem creating schedule search and doing auto lookup. We have tried it and its causing issues.
We have tested using collect to dump it to db index from winevent viewer index. So I have my data in two events now which again has to be merged to make it CIM compliant. This is where I am looking for some help.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...