Schematize custom data

Use Auto-schema to generate Common Information Model (CIM) mappings and deployment artifacts.

Use the Schematize custom data scenario when you need to create a schema for data. Auto-schema analyzes representative sample events, recommends Common Information Model (CIM) mappings, generates field extractions, and creates files or packages that you can deploy outside Guided Onboarding.

Complete the Schematize data workflow

The workflow consists of the following phases:

  • Add representative sample events by entering text, using chat, or uploading a file.
  • Review detected data groups and AI-assisted CIM data model recommendations.
  • Select CIM data models for each detected data group.
  • Review generated field extractions, field calculations, the CIM mappings, and make necessary changes using the chat assistant.
  • Generate schema-on-read files or schema-on-write SPL2 output.

Choose output by destination

The destination that you select determines the type of output that Guided Onboarding generates:

Splunk index
Generate an add-on package for search-time field extractions and the Common Information Model (CIM) mappings. The package can include files such as props.conf and transforms.conf.
Machine Data Lake
Generate SPL2 output for ingest-time schema mapping and transformation.

Map data to the CIM

Use the Common Information Model (CIM) mappings to standardize field names and event types for normalized search and analytics. Map custom data to the CIM to support CIM-based dashboards, detections, and searches in Splunk products such as Splunk Enterprise Security.