Knowledge Management

Writing our first custom App for Avecto chassis_type CIM model

jonxilinx
Path Finder

Hi, Looking for some advice
We have an Asset field trying to get into CIM compliance

ChassisType =   Laptop, Notebook,Docking Station,Desktop,Server etc

What is the most appropriate field in the CIM Inventory event dataset to write this too?

We have other sources of inventory and would like to map for inventory type reports

0 Karma
1 Solution

micahkemp
Champion

I'm not sure that ChassisType, as you have detailed it in your question, maps to any of the CIM Inventory datamodel fields. I didn't see one that seemed to fit.

Keep in mind that when conforming to the CIM, you will almost certainly have fields in your events that don't correlate to CIM fields. This doesn't mean your data is wrong, or that the CIM is incomplete. Instead the CIM exists in order to provide a common set of fields that are used frequently enough to justify having a normalized name.

View solution in original post

0 Karma

mh2112
New Member

Hey there jonxilinx,

You most certainly could use a field alias to map ChassisType to an appropriate field in the Inventory data model. Maybe the vendor_product field? Totally depends on how robust your environment is, how this new addition could affect any other searches using the Inventory DM (your aforementioned inventory type report), and personal preference on labeling.

In case you have not seen these, here is a link to the CIM reference table documentation - https://docs.splunk.com/Documentation/CIM/4.12.0/User/ComputeInventory

0 Karma

micahkemp
Champion

I'm not sure that ChassisType, as you have detailed it in your question, maps to any of the CIM Inventory datamodel fields. I didn't see one that seemed to fit.

Keep in mind that when conforming to the CIM, you will almost certainly have fields in your events that don't correlate to CIM fields. This doesn't mean your data is wrong, or that the CIM is incomplete. Instead the CIM exists in order to provide a common set of fields that are used frequently enough to justify having a normalized name.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...