Knowledge Management

Writing our first custom App for Avecto chassis_type CIM model

jonxilinx
Path Finder

Hi, Looking for some advice
We have an Asset field trying to get into CIM compliance

ChassisType =   Laptop, Notebook,Docking Station,Desktop,Server etc

What is the most appropriate field in the CIM Inventory event dataset to write this too?

We have other sources of inventory and would like to map for inventory type reports

0 Karma
1 Solution

micahkemp
Champion

I'm not sure that ChassisType, as you have detailed it in your question, maps to any of the CIM Inventory datamodel fields. I didn't see one that seemed to fit.

Keep in mind that when conforming to the CIM, you will almost certainly have fields in your events that don't correlate to CIM fields. This doesn't mean your data is wrong, or that the CIM is incomplete. Instead the CIM exists in order to provide a common set of fields that are used frequently enough to justify having a normalized name.

View solution in original post

0 Karma

mh2112
New Member

Hey there jonxilinx,

You most certainly could use a field alias to map ChassisType to an appropriate field in the Inventory data model. Maybe the vendor_product field? Totally depends on how robust your environment is, how this new addition could affect any other searches using the Inventory DM (your aforementioned inventory type report), and personal preference on labeling.

In case you have not seen these, here is a link to the CIM reference table documentation - https://docs.splunk.com/Documentation/CIM/4.12.0/User/ComputeInventory

0 Karma

micahkemp
Champion

I'm not sure that ChassisType, as you have detailed it in your question, maps to any of the CIM Inventory datamodel fields. I didn't see one that seemed to fit.

Keep in mind that when conforming to the CIM, you will almost certainly have fields in your events that don't correlate to CIM fields. This doesn't mean your data is wrong, or that the CIM is incomplete. Instead the CIM exists in order to provide a common set of fields that are used frequently enough to justify having a normalized name.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...