Configuring OCSF CIM add-on
- On Splunk Platform, access the app configuration page by going to Manage apps and then scrolling to the OCSF CIM add-on from the list.
- Select Set up.
- Configure OCSF sourcetypes by selecting all the sourcetypes that contain OCSF-formatted data and to which you want to apply the OCSF field extractions.
- Navigate to OCSF-CIM TA Setup page to configure sourcetypes. You must prefix OCSF sourcetypes with
ocsf. For example,ocsf:aws:asl
- Navigate to OCSF-CIM TA Setup page to configure sourcetypes. You must prefix OCSF sourcetypes with
$SPLUNK_HOME/etc/apps/ocsf_cim_addon_for_splunk/local/props.conf that contains the necessary field extractions.