Splunk Enterprise Security

Why Splunk CIM does not apply tags but 'Search & Reporting' does?

DEAD_BEEF
Builder

Within Splunk ES, I have two tags applied based on Event types and cannot for the life of me get it to apply when attempting to validate the data model and the data. Of all things, the only field not working is the tag field. I even made an alias for tag, which I think is pointless since the original field is called tag already. Are there any suggestions besides admitting I have lost my sanity?

alt text

0 Karma
1 Solution

DEAD_BEEF
Builder

My two tags were not listed in the tag whitelist. Adding them there solved the problem. Add them under
ES > CIM Setup > Intrusion Detection and adding the two tags to the tags whitelist

View solution in original post

DEAD_BEEF
Builder

My two tags were not listed in the tag whitelist. Adding them there solved the problem. Add them under
ES > CIM Setup > Intrusion Detection and adding the two tags to the tags whitelist

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...