All,
I just happened to notice that source=strea:Splunk_SSLActivity from Splunk stream isn't tagged with tag=certificate as I believe is outlined in CIM https://docs.splunk.com/Documentation/CIM/4.12.0/User/Certificates
Is this an oversight/bug or am I misunderstanding the process on that?
a bug has been filed for this in STREAM-3970, please open a Support case if you happen to need an update on status.
expected to be tagged with certificate in the Stream 7.1.3 release.