Release notes for the Splunk Common Information Model Add-on
New features or enhancements
Version 8.6.0 of the Common Information Model (CIM) includes the following new enhancement:
| Enhancement | Description |
|---|---|
| Extend the vulnerability data model with new fields | A number of fields were added to the Vulnerability data model to enhance analytics, correlation, and detection capabilities. These fields cover CVSS scoring details, metadata from threat intelligence sources such as CISA Known Exploited Vulnerabilities and additional enrichment fields such as product version and external references. These fields help to support advanced use cases such as contextual risk scoring, prioritization, and dynamic vulnerability triage. |
Upgrade requirements
| Splunk platform version | Upgrade activity |
|---|---|
| 8.0.x or later | If you apply custom tags to data mapped to CIM data models and you use these tags in searches and search filters, add these tags to the allowlists for those models. See Set up the Splunk Common Information Model Add-on for details about the tags allow list field. |
Compatibility
Version 5.0.x and higher of the Splunk Common Information Model Add-on requires Splunk platform version 8.0.x or higher. Some workarounds, such as the data models spec workaround for tags_allowlist and poll_buckets, are no longer available in version 7.0.x and higher. This might lead to btool check warnings at startup.
Fixed issues
CIM version 8.6.0 of the Splunk Common Information Model Add-on fixes the following issues. If this section is empty, this release has no reported fixed issues.
| Issue | Date fixed | Description |
|---|---|---|
| CIM-1102 | 07-05-2026 | AuditTrail events incorrectly set the src field when app=splunk. |
| CIM-1282 | 04-30-2026 | The Web Datamodel must include signature and signature_id fields. |
| CIM-1029 | 07-19-2026 | File hash or Process hash fields are ambiguous. |
| CIM-1306 | 06-02-2026 | Endpoint data model is missing the following inherited fields: _time, host, source and sourcetype . |
| CIM-1501 | 06-03-2026 | Discrepancy between CIM documentation and the app configuration for src_port field type. |
| CIM-1517 | 05-14-2026 | CIM setup view shows An error occurred fetching assets. Please try again for Splunk Cloud Classic stacks. |
Limitations
If you are in a search head cluster environment on Splunk Cloud Platform, you might see error messages related to adaptive response actions. To troubleshoot these issues, see Troubleshoot adaptive response actions in search head cluster deployments on Splunk Cloud Platform.
Known issues
This version of the Splunk Common Information Model Add-on has the following reported known issues. If this section is empty, this release has no reported known issues.
Deprecated or removed features
The following are deprecated or removed features:
As of version 8.6.0:
- N/A
As of version 8.5.0:
- N/A
As of version 6.4.0:
- N/A
As of version 6.3.0:
- N/A
As of version 6.2.0:
- N/A
As of version 6.1.0:
- N/A
As of version 6.0.4:
- N/A
As of version 6.0.3:
- N/A
As of version 6.0.2:
- N/A
As of version 6.0.1:
- N/A
As of version 6.0.0:
- N/A
As of version 5.3.3:
- N/A
As of version 5.3.2:
- N/A
As of version 5.3.1:
- N/A
As of version 5.2.0:
- N/A
As of version 5.1.1:
- N/A
As of version 5.1.0:
- N/A
As of version 5.0.1:
- N/A
As of version 5.0.0:
- N/A
As of version 4.20.2:
- N/A
As of version 4.20.0:
- N/A
As of version 4.19.0:
- N/A
As of version 4.18.0:
- The
bodyfield is deprecated in favor of thedescriptionfield in the Alerts data model and will be removed in a future version. - The
subjectfield is deprecated in favor of thesignaturefield in the Alerts data model and will be removed in a future version.
As of version 4.15.0:
- The Predictive Analytics dashboard is removed in favor of Machine Learning Toolkit functionality.
As of version 4.14.0:
- The Predictive Analytics dashboard is deprecated in favor of Machine Learning Toolkit functionality and will be removed in a future version.
As of version 4.13.0:
- N/A
Third-party software attributions
The Splunk Common Information Model Add-on does not incorporate any third-party software or libraries.