Is it possible to use data models from Common Information Model to use cases in splunk, if so, how can we do that
Yes, it is possible. That is a big part of what makes Enterprise Security work. You can examine existing correlation searches to see how they use datamodels for various use cases.