- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can I create out of box use cases from Splunk CIM data models ?
jm1
New Member
10-06-2021
08:30 AM
Is it possible to use data models from Common Information Model to use cases in splunk, if so, how can we do that
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
10-06-2021
11:48 AM
Yes, it is possible. That is a big part of what makes Enterprise Security work. You can examine existing correlation searches to see how they use datamodels for various use cases.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
