Knowledge Management

Field Name Recommendation - CIM?

daniel333
Builder

We have a common field in our log to track user activity which we currently call "dye". We're in the process of changing this at this time. So I can name it what ever I want. Skimming CIM docs I don't see anything that jumps out at me.

Anyone in the know with CIM, have a recommendation for me? I feel like there should be a CIM field for sessionID or userjavasession or something like that. Any recommendations?

0 Karma

muebel
SplunkTrust
SplunkTrust

You can find the various Data Models utilized by the CIM here : http://docs.splunk.com/Documentation/CIM/latest/User/Web

The Web DM is in that link, but you can see the rest of them on the left hand side. It sounds like the Web DM might be what you're interested in, but let me know how it works out.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...