Splunk Enterprise Security

Enterprise Security: where is the CIM compatibility breakdown per sourcetype for Splunk_TA_symantec-ep?

danielbb
Motivator

Looking at Splunk_TA_symantec-ep and I wonder where the documentation for the sourcetypes, which are CIM compliant, is.

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Here you go https://docs.splunk.com/Documentation/AddOns/released/SymantecEP/Sourcetypes , that has each source type mapped with CIM datamodels.

View solution in original post

harsmarvania57
Ultra Champion

Hi,

Here you go https://docs.splunk.com/Documentation/AddOns/released/SymantecEP/Sourcetypes , that has each source type mapped with CIM datamodels.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...