Splunk Enterprise Security

Splunk ES and CIM compatibility for upgrade?

spectrum2035
Explorer

Hello,

We would like to use the latest CIM version (4.13.0) in order to use the Endpoint datamodel which is not available in the earlier CIM version.

Our Splunk ES is on 5.1.0 with CIM (4.11.0).

If I upgrade CIM without upgrading the Splunk ES, will that be an issue?

Labels (1)
0 Karma
1 Solution

amitm05
Builder

I think your CIM compatibility has to be with Splunk Versions which needs to be 7.2 OR 7.1 for CIM 4.13.

And then your ES App also has to be compatible with Splunk Versions which in your case is -
5.1 (ES) which goes with 7.1 OR 7.2.

So, your CIM and ES App would be compatible to each other.
You can refer the compatible versions of CIM, ES App and Splunk from here -
https://splunkbase.splunk.com/app/263/

Please accept as answer if this responds to your query, Thanks.

View solution in original post

pellegrini
Path Finder

The release note of ES lists the preferred CIM version. For ES there is no longer any info about supported CIM versions in Splunkbase.

https://docs.splunk.com/Documentation/ES/7.0.1/RN/Enhancements#Updated_add-ons

0 Karma

amitm05
Builder

I think your CIM compatibility has to be with Splunk Versions which needs to be 7.2 OR 7.1 for CIM 4.13.

And then your ES App also has to be compatible with Splunk Versions which in your case is -
5.1 (ES) which goes with 7.1 OR 7.2.

So, your CIM and ES App would be compatible to each other.
You can refer the compatible versions of CIM, ES App and Splunk from here -
https://splunkbase.splunk.com/app/263/

Please accept as answer if this responds to your query, Thanks.

spectrum2035
Explorer

Thanks amitm05

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...