Install the Splunk Common Information Model Add-on
- Download the Common Information Model add-on from Splunkbase at https://apps.splunk.com/app/1621/.
- Review the indexes defined in CIM.
- The previously deprecated
cim_summary
index definition is now removed. If you have a custom configuration for this in your localindexes.conf
file, it will persist as-defined.- If you are no longer using this index definition, remove the stanza from your local
indexes.conf
file before installation. - If you are still using it, you will need to revise the stanza if you were previously relying on parts of the deprecated default
cim_summary
index definition.
- If you are no longer using this index definition, remove the stanza from your local
- The
cim_modactions
index definition is used with the common action model alerts and auditing. Make sure that the index exists and assign the appropriate Roles to search the index.
- The previously deprecated
Install the Splunk Common Information Model Add-on to your search heads only.
Refer to Installing add-ons for detailed instructions describing how to install a Splunk add-on in the following deployment scenarios:
Next: See Set up the Splunk Common Information Model Add-on to perform optional configurations to improve performance.
Overview of the Splunk Common Information Model | Set up the Splunk Common Information Model Add-on |
This documentation applies to the following versions of Splunk® Common Information Model Add-on: 5.0.1, 5.0.2, 5.1.0, 5.1.1, 5.1.2, 5.2.0, 5.3.1, 5.3.2, 6.0.0, 6.0.1
Feedback submitted, thanks!