Splunk Enterprise Security

How to find out which data model a particular app maps to?

tmkunte
Engager

How do I find out which data model a particular app "maps" to?

Specifically the Cisco security suite ...

I see it is CIM compatible and need to get that data into my SIEM

Labels (1)
0 Karma

nvonkorff
Path Finder

Hi @tmkunte 

I recently wrote an app (Data model wrangler) that helps with identifying indexes and sourcetypes that are mapped to data models and calculates two scores to determine an overall health-check of mapping:

  • Mapping quality - Percent of recommended fields in the data model that are found in each index/sourcetype
  • Data quality - Percent coverage of each field within the data, e.g. 25% of events have the 'src' field present

It also provides a field-level view of mapped data to determine which fields are present/missing and which fields have a low data quality.

This may help to give a better understanding of what is mapped to each data model. It is also useful when trying to map custom sourcetypes to data models.

0 Karma

ryanoconnor
Builder

The Cisco Security Suite App https://splunkbase.splunk.com/app/525/ searches data from a number of different cisco devices. Many of those devices have their own individual Technology Add-ons.

Those specific technology add-ons are what you're going to want to look at. They will have tags that determine which data model the data is going to go into. The Splunk Add-on for Cisco ASA is a great example. https://splunkbase.splunk.com/app/1620/

For more information on which tags go to which data models you can look at specific data models here: http://docs.splunk.com/Documentation/CIM/latest/User/Overview

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...