Common Information Model
The Splunk App for Enterprise Security, 3.0 uses the Splunk Common Information Model add-on. It no longer includes the the SA-CommonInformationModel supporting add-on.
See the Common Information Model Add-on Manual for information about the add-on, including reference information about fields, tags, and data model objects and constraints.
Dashboard requirements matrix | More resources |
This documentation applies to the following versions of Splunk® Enterprise Security: 3.0, 3.0.1
Feedback submitted, thanks!