Splunk Enterprise Security

Enterprise Security: For each ES rule to work, which CIM tags and fields are required and which fields are optional?

laurie_gellatly
Communicator

The CIM model shows which tags are required for that model's ES rules to be active but I still need to ensure that the fields required by each rule are also provided. At present I have to look at the rule's search to determine which fields it requires.
Is there any documentation that shows for ES rule X, tag y and fields a, b and c are required while fields e and f are optional?

i.e. "Access - Excessive Failed Logins - Rule" requires a tag of "authentication", field 'action' must be set to 'failure', 'user' and 'dest' must be set to something useful. 'app' and 'src' are optional.
Looking at these requirements I can see what my own extraction needs to provide for this rule to be active.

Thanks ...Laurie:{)

mcronkrite
Splunk Employee
Splunk Employee

Take a look at this section of the ES Documentation - Mapping Data Sources section that shows what data is needed for each dashboard and has troubleshooting searches to find missing data. Access and the rest are listed.

And then also look at this Dashboard Requirements Matrix for a quick reference as to the fields needed. Any non-mapped fields will have "unknown" as the value.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...