CIM non-compliance alert setup examples by data source
The following table lists the best practice configurations for the Common Information Model (CIM) data model, datasets, and fields needed to monitor for each supported data source. Use this as a reference when configuring CIM compliance alert rules in Splunk Ingest Monitoring.
| Data model and dataset | Source type | Fields |
|---|---|---|
| Performance.All_Performance.CPU | aws:cloudwatch | dest, cpu_load_percent |
| Network_Sessions.All_Sessions.VPN | cisco:asa | dest_ip, user, vendor_product |
| Network_Resolution.DNS | crowdstrike:events:sensor | answer, message_type, query, reply_code, reply_code_id, vendor_product |
| Change.All_Changes.Account_Management | google:gcp:pubsub:audit:admin_activity | action, change_type, command, dest, dvc, object, object_attrs, object_category, object_id, object_path, result, result_id, src, status, user, vendor_product |
| Network_Traffic.All_Traffic | flowintegrator | action, bytes, bytes_in, bytes_out, dest, dest_port, dvc, rule, src, src_port, transport, vendor_product |
| Data_Access.Data_Access | o365:management:activity | action, app, dest, object, object_category, src, vendor_account, user, vendor_product |
| Authentication. Authentication | ms:aad:signin | action, app, dest, src, user |
| Authentication. Authentication | pan:globalprotect | action, app, dest, src, src_user, user |
| Authentication. Failed_Authentication | OktaIM2:log | action, app, dest, src, src_user, user |