Hi! I'm late to the party with this answer, but yes, you can use Endpoint for that. The Endpoint doc has been updated with further details... The Endpoint data model is for monitoring endpoint clients including, but not limited to, end-user machines, laptops, and bring your own devices (BYOD). If an event is about an endpoint process, service, file, port, and so on, then it relates to the Endpoint data model. For administrative and policy types of changes to infrastructure security devices, servers, and endpoint detection and response (EDR) systems, see Change.Endpoint in the Change data model. https://docs.splunk.com/Documentation/CIM/4.18.0/User/Endpoint
... View more