Hi bro sorry for the late reply went to go make dinner for four years. If I understand your issue correctly, you are having issues finding your authentication CIM via data model search. In order to map your authentication logs to authentication CIM, you can add the following lines into your tags.conf file (located in TA): [eventtype=[..]] authentication = enabled If you are unsure of your eventtype, you should also have eventtypes.conf where you can map the sourcetype to eventtype. Hope this clarifies your doubts, I will go eat my dinner now.
... View more