hello team
i am working on Enterprise Security version 5.1.0 (splunk version7.2.3)
Although there are some correlation searches that use Endpoint Datamodel, in datamodel list I can not find any Endpoint Datamodel !
for example I have Change Anaysis OR Application state Datamodel but there is no Endpoint Datamodel !
I Was wondering where the Endpoint DataSet/Datamodel is ?
Or how can I add it ?
Thanks
Upgrade the CIM add-on to version 4.12 or newer.