Getting Data In

Is there a supported or working CIM Mapping add on for "Cisco Cloud Security Umbrella Add on"?

ojay
Path Finder

Hi all,

I am using "Cisco Cloud Security Umbrella Addon for Splunk" to ingest the Data via API.

https://splunkbase.splunk.com/app/5557/

Unfortunately the add-on does not include any CIM knowledge. 

Can anyone tell me if there is a supported or working add-on for the CIM Mapping?

 

Thank you

O.

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you can't find anything suitable on splunkbase, then you'll have to create your own CIM mapping.  Examine the available fields then add the necessary EVAL, EXTRACT, or FIELDALIAS commands to create CIM fields for the datamodel(s) you plan to use.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...