The Gigamon CIM Add-On is a specialized extension for Splunk designed to streamline the integration and normalization of Gigamon data (Data ingested in JSON format) within the Common Information Model (CIM). This add-on facilitates the mapping of Gigamon-specific fields to the corresponding CIM data model, enhancing the overall visibility and comprehension of Gigamon-generated data within the Splunk platform. As part this we have also created a new Datamodel named "Gigamon: this has 4 new datasets 1) DNS 2) Certificates 3) web 4) Network Traffic. There are 19 attributes corresponding to this. sourcetype=gigamon:traffic Name Tag(s) dns_host_addr gigamon_dns dns_tunneling gigamon_dns http_code gigamon_web http_content_encoding gigamon_web http_file_type gigamon_web http_rtt gigamon_web http_server gigamon_web http_server_agent gigamon_web http_uri gigamon_web http_user_agent gigamon_web http_version gigamon_web ip_wrong_crc gigamon_communicate gigamon_network ssl_cipher_suite_id gigamon_certificate gigamon_ssl ssl_ext_sig_algorithm_scheme gigamon_certificate gigamon_ssl tcp_flag_reset gigamon_communicate gigamon_network tcp_loss_count gigamon_communicate gigamon_network tcp_rtt gigamon_communicate gigamon_network tcp_rtt_app gigamon_communicate gigamon_network tcp_wrong_crc gigamon_communicate gigamon_network
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources