Configure global field mappings
Use global field mappings when you have mappings that you want to apply for all your data model and saved search exports. Global field mappings provide consistency in the CEF mappings for events sent to Splunk Phantom, and can also save you time when configuring your data model or saved search exports.
How global field mappings are created
Global field mappings are created when you configure or edit event forwarding. For example:
- Configure a new data model or saved search export. See Create a data model export to send data to Splunk Phantom or Create a saved search export to send data to Splunk Phantom.
- Configure your desired mappings for the unmapped fields, then click Save Mappings to save the mappings as global field mappings.
The next time you configure a data model or saved search export, any fields that are mapped with global field mappings will appear in the Mapped Fields section. Global field mappings are only applied to new data model or saved search export configurations and not to any existing event forwarding configurations.
Global field mappings are created automatically for Splunk Enterprise Security (ES) notable events.
If you map a field that already exists as a global field mapping, the existing global field mapping is overwritten.
Updating CIM to CEF mappings when accessing the global field mappings for the first time
The first time you access the Global Field Mapping page, the default CIM-to-CEF mappings defined in Splunk Phantom are displayed. Configure and save the desired mappings to use them in your saved searches and data models. The default CIM-to-CEF mappings are not displayed again when you access the Global Field Mapping page any subsequent time.
Forward unmodified data to Splunk Phantom
Delete a global field mapping to send the raw, unmodified data to Splunk Phantom.
Perform the following tasks to delete a global field mapping:
- In your Splunk platform instance, access the Splunk Phantom App for Splunk.
- Click Configure Global Field Mappings.
- Click Delete for the field mapping you want to delete.
- Click Delete in the dialog box to confirm that you want to delete the mapping.
Create a saved search export to send data to Splunk Phantom | Troubleshoot event forwarding |
This documentation applies to the following versions of Splunk® Phantom App for Splunk: 3.0.5, 4.0.10, 4.0.35
Feedback submitted, thanks!