Knowledge Management

Is there any way to verify CIM compliance of an app being developed?

prabhasgupte
Communicator

Is there any way to verify whether the app being developed is CIM compliant? I came to know that, if it is CIM compliant, the Splunk ES app should be able to show data indexed by this app. BUT, the ES app is not free to download, nor a trial version is available.

What could be other way to verify compliance?

Tags (2)
1 Solution

kheli
Path Finder

Use the pivot within each data model. If u can search the events then they are CIM compliant for that data model

View solution in original post

0 Karma

rcorbisier_splu
Splunk Employee
Splunk Employee

If you haven’t seen it yet, you might want to check out the Splunk reference app with associated developer guidance that was built by a Splunk dev team. The current version covers app development topics from getting your data into Splunk Enterprise to building custom reporting through testing and packaging your app. There’s code and tests you can use and the development process is fully documented.

This is an ongoing dev effort by the team so check back often to see what’s been added. Also, feel free to post requests for future improvements and even contribute by reporting bugs or submitting pull requests.

0 Karma

kheli
Path Finder

Use the pivot within each data model. If u can search the events then they are CIM compliant for that data model

0 Karma

prabhasgupte
Communicator

Oh, that's nice! Thanks!!

0 Karma

satishsdange
Builder
0 Karma

prabhasgupte
Communicator

So, you mean to say that, if I get to see my data in those pivots, I could rest assured that it is normalized properly and that it is CIM compliant?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...