All Apps and Add-ons

Easy way to add access_combined to the Web Data Model

sloshburch
Splunk Employee
Splunk Employee

This question is not just asking about how to generally add data to a CIM (http://docs.splunk.com/Documentation/CIM/latest/User/UsetheCIMtonormalizedataatsearchtime)

Many apps come with sourcetypes predefined and ready to go with eventtypes and tags so they work with Common Information Model Data Models immediately (AWS TA for example). I'm not seeing anything like that for access_combined. Am I missing something obvious here? If there exists a definition of the eventtype, tags, field aliases, etc.. then I'd love to use that instead of building it on my own.

1 Solution

gfuente
Motivator

Have you checked this addon?

https://splunkbase.splunk.com/app/3186/#/overview

You may just need to change the sourcetype to apache:access

Reagrds

View solution in original post

aivarson_splunk
Splunk Employee
Splunk Employee

Just created an add-on for this in case you don't want to change your sourcetype from the out of the box access_combined: https://splunkbase.splunk.com/app/3434/

sloshburch
Splunk Employee
Splunk Employee

I'll check it out. Assuming it works I'll probably switch the accepted answer to this one.

0 Karma

gfuente
Motivator

Have you checked this addon?

https://splunkbase.splunk.com/app/3186/#/overview

You may just need to change the sourcetype to apache:access

Reagrds

sloshburch
Splunk Employee
Splunk Employee
0 Karma

sloshburch
Splunk Employee
Splunk Employee

Thanks. I'm also reaching out to the docs team to ask them to reference https://splunkbase.splunk.com/apps/#/page/1/search/CIM-compatible/order/relevance/supported/splunk if not done already. I think it's good to highlight those options.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...