i have installed theSplunkAdd-on for Windows app to monitor DNS logs using the Debugging enabled option on my server. i am seeing the events ingesting with the proper source type of MSAD:NT6:DNS b...
...ourcetype was set to "ossec_alerts".
Since this App is not CIM compatible, we had to install "SplunkAdd-on for OSSEC" Add-on and change the sourcetype to "ossec". After this change, we lost all the o...
...hy this is occurring. Do we need to installthe infblox app onthe indexer as well? This breaks SplunkCommonInformationModel (CIM) compliance and by extension Splunk Enterprise Security. Any a...
Hi Except if i am mistaken, Splunk ES contains a collection of add-ons. In combination, these add-ons provide the dashboards, searches, and tools that summarize the security posture of the e...
Hi,
I have a existing dlp data model, Can we addthe indexed dlp data to exisiting one to make a cim compliant OR we need to create a new datamodel to addthe data ?