Splunk® Common Information Model Add-on

Common Information Model Add-on Manual

This documentation does not apply to the most recent version of Splunk® Common Information Model Add-on. For documentation on the most recent version, go to the latest release.

Release notes for the Splunk Common Information Model Add-on

Version 4.1.1 involves no user-facing changes from CIM version 4.1.0. Access the release notes for 4.1.0 to see new features and fixed issues of interest to users.

Fixed issues

Version 4.1.1 of the Splunk Common Information Model Add-on fixes the following issue.

Resolved date Defect number Description
3/30/14 CIM-293 Packaging changes resulting in new release with new maintenance version.

Known issues

Version 4.1.1 of the Splunk Common Information Model Add-on has the following known issues:

Date Defect number Description
11/12/14 CIM-252 Field "entry" for Network Resolution data model is not needed and should be removed.
11/12/14 CIM-251 Field "time_submitted" in Ticket Management data model should be a time, not a string.
11/06/14 CIM-248 Field "file_size" in Change Analysis data model should be a number, not a string.
11/05/14 CIM-247 Field "icmp_type" in Network Traffic data model should be a number, not a string.
10/24/14 CIM-252 BaseEvent object hierarchy makes accelerated search unwieldy.
10/03/14 CIM-221 Field extraction should avoid variable keys whenever possible.
10/03/14 CIM-220 Event types should avoid KV whenever possible.
07/07/14 CIM-169 Remote search log warning messages from acceleration due to long search strings. Workaround: turn off truncation on indexers in etc/system/local/props.conf as shown:

[splunkd_remote_searches]

TRUNCATE = 0

10/11/13 CIM-85 Inconsistent use of url and uri in Web data model fields.

Third-party software attributions

Version 4.1.1 of the Splunk Common Information Model Add-on does not incorporate any third-party software or libraries.

Last modified on 17 April, 2015
Install the Splunk Common Information Model Add-on   Support and resource links for the Splunk Common Information Model Add-on

This documentation applies to the following versions of Splunk® Common Information Model Add-on: 4.1.1








You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters