I have some event, with report and vulnerability tags. I have also set global permissions to this event, so that other apps could see it.
However, when I use Splunk CIM add-on, it does not recognize it. It neither shows the eventtype, nor the tags. It says "Eventtype 'my-event' does not exist or is disabled". Whereas, the event does exist and is enabled.
If I use default search 'Search and Reporting' app, I can see the proper eventtype and tags.
What is missing or going wrong?
hope you are aware of "DataModels" within CIM? You need to baseline your data to a relevant DataModel and tag correctly and have relevant fields.
Yes, I do have my data fields mapped to those of "Vulnerabilities" data model. (mapped through field aliases and lookup tables.) But still I face this problem. What could be the reason?