Splunk Cim Data Model Setup

Use when the user asks to accelerate a CIM data model, constrain CIM data model indexes, map data to CIM with tags and eventtypes, fix CIM compliance, or manage datamodels.conf for CIM or custom data models. Not for Enterprise Security-specific acceleration, which lives in splunk-enterprise-security-config. Render, validate, and apply Splunk Common Information Model (CIM) data model governance: install handoff for the CIM add-on (Splunk_SA_CIM), data model acceleration settings, allowed-index constraint macros (cim_<model>_indexes), and CIM eventtype/tag mapping to make sourcetypes CIM-compliant, with tstats validation.

chambear2809 Updated

File contents

chambear2809/splunk-cisco-skills/tree/main/skills/splunk-cim-data-model-setup commit 03fb5b1242

Frequently asked questions

npx skillmds@latest add chambear2809/splunk-cim-data-model-setup