Release notes for the Splunk Common Information Model Add-on
Version 6.4.0 of the Splunk Common Information Model Add-on was released on February 4, 2026.
New features or enhancements
Version 6.4.0 of the Common Information Model (CIM) includes additional business unit fields to the Data Access data model to support asset and identities, and a few other fields to Network Sessions, Network Traffic, and Endpoint data models.
Upgrade requirements
| Splunk platform version | Upgrade activity |
|---|---|
| 8.0.x or later | If you apply custom tags to data mapped to CIM data models and you use these tags in searches and search filters, add these tags to the allowlists for those models. See Set up the Splunk Common Information Model Add-on for details about the tags allow list field. |
Compatibility
Version 5.0.x and higher of the Splunk Common Information Model Add-on requires Splunk platform version 8.0.x or higher. Some workarounds, such as the data models spec workaround for tags_allowlist and poll_buckets, are no longer available in version 7.0.x and higher. This might lead to btool check warnings at startup.
Fixed issues
CIM version 6.4.0 of the Splunk Common Information Model Add-on fixes the following issues. If this section is empty, this release has no reported fixed issues.
| Date resolved | Issue number | Description |
|---|---|---|
| 2025-12-10 | CIM-1076 | The Endpoint data model needs an additional user field for some datasets. |
| 2025-12-10 | CIM-1083 | The Network Traffic data model needs a process_guid field. |
| 2025-11-25 | CIM-1074 | The Network Sessions data model lacks a field to store the device reporting the log versus the splunk host. |
| 2026-01-13 | CIM-1457 | Asset and identity information is not available for Data Access data model |
Limitations
If you are in a search head cluster environment on Splunk Cloud Platform, you might see error messages related to adaptive response actions. To troubleshoot these issues, see Troubleshoot adaptive response actions in search head cluster deployments on Splunk Cloud Platform.
Known issues
This version of the Splunk Common Information Model Add-on has the following reported known issues. If this section is empty, this release has no reported known issues.
Deprecated or removed features
The following are deprecated or removed features:
As of version 6.4.0:
- N/A
As of version 6.3.0:
- N/A
As of version 6.2.0:
- N/A
As of version 6.1.0:
- N/A
As of version 6.0.4:
- N/A
As of version 6.0.3:
- N/A
As of version 6.0.2:
- N/A
As of version 6.0.1:
- N/A
As of version 6.0.0:
- N/A
As of version 5.3.3:
- N/A
As of version 5.3.2:
- N/A
As of version 5.3.1:
- N/A
As of version 5.2.0:
- N/A
As of version 5.1.1:
- N/A
As of version 5.1.0:
- N/A
As of version 5.0.1:
- N/A
As of version 5.0.0:
- N/A
As of version 4.20.2:
- N/A
As of version 4.20.0:
- N/A
As of version 4.19.0:
- N/A
As of version 4.18.0:
- The
bodyfield is deprecated in favor of thedescriptionfield in the Alerts data model and will be removed in a future version. - The
subjectfield is deprecated in favor of thesignaturefield in the Alerts data model and will be removed in a future version.
As of version 4.15.0:
- The Predictive Analytics dashboard is removed in favor of Machine Learning Toolkit functionality.
As of version 4.14.0:
- The Predictive Analytics dashboard is deprecated in favor of Machine Learning Toolkit functionality and will be removed in a future version.
As of version 4.13.0:
- N/A
Third-party software attributions
The Splunk Common Information Model Add-on does not incorporate any third-party software or libraries.