Splunk Enterprise Security

Splunk ES and CIM compatibility for upgrade?

spectrum2035
Explorer

Hello,

We would like to use the latest CIM version (4.13.0) in order to use the Endpoint datamodel which is not available in the earlier CIM version.

Our Splunk ES is on 5.1.0 with CIM (4.11.0).

If I upgrade CIM without upgrading the Splunk ES, will that be an issue?

Labels (1)
0 Karma
1 Solution

amitm05
Builder

I think your CIM compatibility has to be with Splunk Versions which needs to be 7.2 OR 7.1 for CIM 4.13.

And then your ES App also has to be compatible with Splunk Versions which in your case is -
5.1 (ES) which goes with 7.1 OR 7.2.

So, your CIM and ES App would be compatible to each other.
You can refer the compatible versions of CIM, ES App and Splunk from here -
https://splunkbase.splunk.com/app/263/

Please accept as answer if this responds to your query, Thanks.

View solution in original post

pellegrini
Path Finder

The release note of ES lists the preferred CIM version. For ES there is no longer any info about supported CIM versions in Splunkbase.

https://docs.splunk.com/Documentation/ES/7.0.1/RN/Enhancements#Updated_add-ons

0 Karma

amitm05
Builder

I think your CIM compatibility has to be with Splunk Versions which needs to be 7.2 OR 7.1 for CIM 4.13.

And then your ES App also has to be compatible with Splunk Versions which in your case is -
5.1 (ES) which goes with 7.1 OR 7.2.

So, your CIM and ES App would be compatible to each other.
You can refer the compatible versions of CIM, ES App and Splunk from here -
https://splunkbase.splunk.com/app/263/

Please accept as answer if this responds to your query, Thanks.

spectrum2035
Explorer

Thanks amitm05

0 Karma
Get Updates on the Splunk Community!

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...