Hello guys,
Does Splunk CIM implementation (after app setup) require admin permissions?
If yes is it needed all the time or it's majorly creating event types/tags as seen at https://docs.splunk.com/Documentation/CIM/4.16.0/User/UsetheCIMtonormalizedataatsearchtime#3._Config... ?
Thanks.