Splunk Enterprise

Is there another way to correctly map data to be CIM compliant?

jip31
Motivator

Hi

I try to list the better ways to map not cCIM compliant data with the good datamodel

Is there a better way to use a field alias?

And is there another way to correctly map data to be CIM compliant?

Last question, if we use an addon like the Splunk Add-on for Windows, does it means that our business data will be automatically updated to be CIM compliant?

Thanks

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...