Latest Version 1.0.3
August 20, 2024
There are unfortunately TAs on Splunkbase that do not fully parse or map the data to Splunk CIM datamodels. Purpose of this application is to provide parsing knowledge objects for different technologies in order to achieve full compliance with CIM. It is recommended to install this application with Infigo SIEM (https://classic.splunkbase.splunk.com/app/7147/) in order to get maximum from your SIEM sollution. Additional parsing and mapping to CIM are most notably done for Sysmon, Cisco eStreamer, Splunk Stream DNS, MS Defender.
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources