Splunk® Common Information Model Add-on

Common Information Model Add-on Manual

Download manual as PDF

This documentation does not apply to the most recent version of CIM. Click here for the latest version.
Download topic as PDF

Install the add-on

This section describes where to get the Splunk Common Information Model Add-on and what you need to do to install and configure it.

Note: The CIM app may be bundled with some applications, and therefore may already be in place in your system. Versions older than 3.0.0 are not implemented as Splunk 6 datamodels and are not considered compatible. The package name has been changed to prevent accidental upgrades.

Download the add-on

Data models implementing the Common Information Model are available as part of the Splunk_SA-CIM add-on available on Splunk Apps. Download the Splunk_SA-CIM Add-on from Splunk Apps to your desktop or local directory.


To install the Splunk_SA_CIM add-on, click Manage Apps on the Splunk Home page. Click Install app from file and browse to the location of the Splunk_SA_CIM add-on in your local directory or desktop. If you are upgrading to a newer version of the add-on, be sure to check the Upgrade option to overwrite your existing version.

Once the Common Information Model add-on is installed, there is no further configuration you need to do, unless you want to accelerate any of the data models.

Note: The data models included in the Splunk_SA_CIM add-on are configured with data model acceleration turned off. See "Enable data model acceleration" in the core Splunk documentation for more details.

Use the Common Information Model

This documentation applies to the following versions of Splunk® Common Information Model Add-on: 4.0.0

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters