Contents
2 Getting Familiar with the Splunk Common Information Model 2
2.1 Getting Familiar with the Splunk Common Information Model 2
2.2 Examining a Few of the CIM Data Models 4
2.3 Splunk Knowledge Objects 4
2.4 Knowledge Objects Included in the CIM 10
3 Configuring the Common Information Model Add-on 13
3.1 Configuring and Employing the Common Information Model Add-on 13
3.2 Introducing Our Use Case 17
3.3 *Demo: Making Data CIM Compliant in Splunk 17
Course Overview
Getting Familiar with the Splunk Common Information Model
Getting Familiar with the Splunk Common Information Model
Examining a Few of the CIM Data Models
https://docs.splunk.com/Documentation/CIM/5.3.1/User/Overview
Data Modal contains 1 or more Data sets
Splunk Knowledge Objects
Knowledge Objects Included in the CIM
Demo: Splunk CIM
Summary
Configuring the Common Information Model Add-on
Configuring and Employing the Common Information Model Add-on
Introducing Our Use Case
*Demo: Making Data CIM Compliant in Splunk
One more time watch
Uploaded system1, 2, 3 csv files with same index = main
Go to the CIM documentation – found web datamadal is suitable for this use case
Settings – Data modal – search Web – it is available (as already we installed CIM)
Apps – Manage Apps – filter cof CIM – Choose Splunk Common Information Model – Set up –
Find the web data model –
Accelerate checked
Indexes whitelist = main
Set up Event Types: Settings – Event Types - Create New Event Types -
Go To CIM – Change Permission from Private to global
Go to Settings – Data Model > Web Data Model – Click Pivot
Click web dataset –
Go to settings – Fields – Field aliases – New Field Alieses
Go to settings – Fields – Field Aliases – we can see the newly added field aliases
File 3 is not name=value – so need to do Field extract from the file
Go to search – search host=”system3” – go to Extract New Fields – Select Method > choose Regex – highlight the value and give the Field Name –
Now – go to settings – Data Model – Web – Pivot – now we get fields
2 single value
Create panels and Save to Dashboard
No comments:
Post a Comment