You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

35 KiB

1datamodelmodelNamenodeNametags_timediffappdata_source_categoryversion
2Alerts.AlertsAlertsAlertsalertSplunk_SA_CIMDS020HostIntrustionDetection-ET01SigDetected5.1.1
3AlertsAlertsalertSplunk_SA_CIMDS020HostIntrustionDetection-ET01SigDetected5.1.1
4Application_State.All_Application_StateApplication_StateAll_Application_StateSplunk_SA_CIM5.1.1
5Application_State.PortsApplication_StatePortslistening,portSplunk_SA_CIM5.1.1
6Application_State.ProcessesApplication_StateProcessesprocess,reportSplunk_SA_CIM5.1.1
7Application_State.ServicesApplication_StateServicesservice,reportSplunk_SA_CIM5.1.1
8Application_StateApplication_StateSplunk_SA_CIM5.1.1
9Authentication.AuthenticationAuthenticationAuthenticationauthenticationSplunk_SA_CIMDS003Authentication-ET01Success|DS003Authentication-ET01SuccessDefault|DS003Authentication-ET01SuccessInsecure|DS003Authentication-ET02Failure|DS003Authentication-ET02FailureBadFactor|DS003Authentication-ET02FailureError|DS003Authentication-ET02FailureUnknownAccount5.1.1
10Authentication.Failed_AuthenticationAuthenticationFailed_AuthenticationauthenticationSplunk_SA_CIMDS003Authentication-ET02Failure5.1.1
11Authentication.Successful_AuthenticationAuthenticationSuccessful_AuthenticationauthenticationSplunk_SA_CIMDS003Authentication-ET01Success5.1.1
12Authentication.Default_AuthenticationAuthenticationDefault_Authenticationauthentication,defaultSplunk_SA_CIM5.1.1
13Authentication.Failed_Default_AuthenticationAuthenticationFailed_Default_Authenticationauthentication,defaultSplunk_SA_CIM5.1.1
14Authentication.Successful_Default_AuthenticationAuthenticationSuccessful_Default_Authenticationauthentication,defaultSplunk_SA_CIMDS003Authentication-ET01SuccessDefault5.1.1
15Authentication.Insecure_AuthenticationAuthenticationInsecure_Authenticationauthentication,insecureSplunk_SA_CIMDS003Authentication-ET01SuccessInsecure5.1.1
16Authentication.Privileged_AuthenticationAuthenticationPrivileged_Authenticationauthentication,privilegedSplunk_SA_CIM5.1.1
17Authentication.Failed_Privileged_AuthenticationAuthenticationFailed_Privileged_Authenticationauthentication,privilegedSplunk_SA_CIM5.1.1
18Authentication.Successful_Privileged_AuthenticationAuthenticationSuccessful_Privileged_Authenticationauthentication,privilegedSplunk_SA_CIM5.1.1
19AuthenticationAuthenticationauthenticationSplunk_SA_CIMDS003Authentication-ET01Success|DS003Authentication-ET01SuccessDefault|DS003Authentication-ET01SuccessInsecure|DS003Authentication-ET02Failure|DS003Authentication-ET02FailureBadFactor|DS003Authentication-ET02FailureError|DS003Authentication-ET02FailureUnknownAccount5.1.1
20Certificates.All_CertificatesCertificatesAll_CertificatescertificateSplunk_SA_CIMDS041Certificates-ET01All5.1.1
21Certificates.SSLCertificatesSSLcertificate,sslSplunk_SA_CIM5.1.1
22CertificatesCertificatescertificateSplunk_SA_CIMDS041Certificates-ET01All5.1.1
23Change.All_ChangesChangeAll_ChangeschangeSplunk_SA_CIMDS037Change-ET01Change|DS037Change-ET02ChangeAccount|DS037Change-ET02ChangeAuditing|DS037Change-ET02ChangeNetwork5.1.1
24Change.Auditing_ChangesChangeAuditing_Changeschange,auditSplunk_SA_CIMDS037Change-ET02ChangeAuditing5.1.1
25Change.Endpoint_ChangesChangeEndpoint_Changeschange,endpointSplunk_SA_CIM5.1.1
26Change.Endpoint_RestartsChangeEndpoint_Restartschange,endpointSplunk_SA_CIM5.1.1
27Change.Other_Endpoint_ChangesChangeOther_Endpoint_Changeschange,endpointSplunk_SA_CIM5.1.1
28Change.Network_ChangesChangeNetwork_Changeschange,networkSplunk_SA_CIMDS010NetworkCommunication-ET02State|DS037Change-ET02ChangeNetwork5.1.1
29Change.Device_RestartsChangeDevice_Restartschange,networkSplunk_SA_CIM5.1.1
30Change.Account_ManagementChangeAccount_Managementchange,accountSplunk_SA_CIMDS037Change-ET02ChangeAccount5.1.1
31Change.Accounts_CreatedChangeAccounts_Createdchange,accountSplunk_SA_CIM5.1.1
32Change.Accounts_DeletedChangeAccounts_Deletedchange,accountSplunk_SA_CIM5.1.1
33Change.Account_LockoutsChangeAccount_Lockoutschange,accountSplunk_SA_CIM5.1.1
34Change.Accounts_UpdatedChangeAccounts_Updatedchange,accountSplunk_SA_CIM5.1.1
35Change.Instance_ChangesChangeInstance_Changeschange,instanceSplunk_SA_CIM5.1.1
36ChangeChangechangeSplunk_SA_CIMDS037Change-ET01Change|DS037Change-ET02ChangeAccount|DS037Change-ET02ChangeAuditing|DS037Change-ET02ChangeNetwork5.1.1
37Change_Analysis.All_ChangesChange_AnalysisAll_ChangeschangeSplunk_SA_CIM5.1.1
38Change_Analysis.Auditing_ChangesChange_AnalysisAuditing_Changeschange,auditSplunk_SA_CIM5.1.1
39Change_Analysis.Endpoint_ChangesChange_AnalysisEndpoint_Changeschange,endpointSplunk_SA_CIM5.1.1
40Change_Analysis.Filesystem_ChangesChange_AnalysisFilesystem_Changeschange,endpointSplunk_SA_CIM5.1.1
41Change_Analysis.Registry_ChangesChange_AnalysisRegistry_Changeschange,endpointSplunk_SA_CIM5.1.1
42Change_Analysis.Endpoint_RestartsChange_AnalysisEndpoint_Restartschange,endpointSplunk_SA_CIM5.1.1
43Change_Analysis.Other_Endpoint_ChangesChange_AnalysisOther_Endpoint_Changeschange,endpointSplunk_SA_CIM5.1.1
44Change_Analysis.Network_ChangesChange_AnalysisNetwork_Changeschange,networkSplunk_SA_CIM5.1.1
45Change_Analysis.Device_RestartsChange_AnalysisDevice_Restartschange,networkSplunk_SA_CIM5.1.1
46Change_Analysis.Account_ManagementChange_AnalysisAccount_Managementchange,accountSplunk_SA_CIM5.1.1
47Change_Analysis.Accounts_CreatedChange_AnalysisAccounts_Createdchange,accountSplunk_SA_CIM5.1.1
48Change_Analysis.Accounts_DeletedChange_AnalysisAccounts_Deletedchange,accountSplunk_SA_CIM5.1.1
49Change_Analysis.Account_LockoutsChange_AnalysisAccount_Lockoutschange,accountSplunk_SA_CIM5.1.1
50Change_Analysis.Accounts_UpdatedChange_AnalysisAccounts_Updatedchange,accountSplunk_SA_CIM5.1.1
51Change_AnalysisChange_AnalysischangeSplunk_SA_CIMDS009EndPointIntel-ET05ObjectChangeRemovableStorage5.1.1
52Cloud_Infrastructure.ComputeCloud_InfrastructureComputecloud,compute,infrastructurecloud-datamodel-security-researchDS036CloudInfrastructure-ET01Compute1.1
53Cloud_Infrastructure.StorageCloud_InfrastructureStoragecloud,storage,infrastructurecloud-datamodel-security-researchDS036CloudInfrastructure-ET02Storage1.1
54Cloud_Infrastructure.TrafficCloud_InfrastructureTrafficcloud,network,traffic,infrastructurecloud-datamodel-security-researchDS036CloudInfrastructure-ET03Traffic1.1
55Cloud_Infrastructure.AuthenticationCloud_InfrastructureAuthenticationcloud,authentication,infrastructurecloud-datamodel-security-researchDS036CloudInfrastructure-ET04Authentication1.1
56Cloud_InfrastructureCloud_Infrastructurecloud,compute,infrastructurecloud-datamodel-security-research1.1
57Compute_Inventory.All_InventoryCompute_InventoryAll_InventorySplunk_SA_CIMDS039ComputeInventory-ET01Inventory5.1.1
58Compute_Inventory.CPUCompute_InventoryCPUinventory,cpuSplunk_SA_CIM5.1.1
59Compute_Inventory.MemoryCompute_InventoryMemoryinventory,memorySplunk_SA_CIM5.1.1
60Compute_Inventory.NetworkCompute_InventoryNetworkinventory,networkSplunk_SA_CIM5.1.1
61Compute_Inventory.StorageCompute_InventoryStorageinventory,storageSplunk_SA_CIM5.1.1
62Compute_Inventory.OSCompute_InventoryOSinventory,system,versionSplunk_SA_CIM5.1.1
63Compute_Inventory.UserCompute_InventoryUserinventory,userSplunk_SA_CIM5.1.1
64Compute_Inventory.Cleartext_PasswordsCompute_InventoryCleartext_Passwordsinventory,userSplunk_SA_CIMDS039ComputeInventory-ET01InventoryCleartext_Passwords5.1.1
65Compute_Inventory.Default_AccountsCompute_InventoryDefault_Accountsinventory,user,defaultSplunk_SA_CIMDS039ComputeInventory-ET01InventoryDefaultUser5.1.1
66Compute_Inventory.Virtual_OSCompute_InventoryVirtual_OSinventory,virtualSplunk_SA_CIM5.1.1
67Compute_Inventory.SnapshotCompute_InventorySnapshotinventory,virtual,snapshotSplunk_SA_CIM5.1.1
68Compute_Inventory.ToolsCompute_InventoryToolsinventory,virtual,toolsSplunk_SA_CIM5.1.1
69Compute_InventoryCompute_InventorySplunk_SA_CIMDS039ComputeInventory-ET01Inventory5.1.1
70DLP.DLP_IncidentsDLPDLP_Incidentsdlp,incidentSplunk_SA_CIMDS016DataLossPrevention-ET01Violation5.1.1
71DLPDLPdlp,incidentSplunk_SA_CIMDS016DataLossPrevention-ET01Violation5.1.1
72Data_Access.Data_AccessData_AccessData_Accessdata,accessSplunk_SA_CIM5.1.1
73Data_AccessData_Accessdata,accessSplunk_SA_CIM5.1.1
74Databases.All_DatabasesDatabasesAll_DatabasesdatabaseSplunk_SA_CIMDS029DatabaseServer-ET01General5.1.1
75Databases.Database_InstanceDatabasesDatabase_Instancedatabase,instanceSplunk_SA_CIM5.1.1
76Databases.Instance_StatsDatabasesInstance_Statsdatabase,instance,statsSplunk_SA_CIM5.1.1
77Databases.Session_InfoDatabasesSession_Infodatabase,instance,sessionSplunk_SA_CIM5.1.1
78Databases.Lock_InfoDatabasesLock_Infodatabase,instance,lockSplunk_SA_CIM5.1.1
79Databases.Database_QueryDatabasesDatabase_Querydatabase,querySplunk_SA_CIM5.1.1
80Databases.TablespaceDatabasesTablespacedatabase,query,tablespaceSplunk_SA_CIM5.1.1
81Databases.Query_StatsDatabasesQuery_Statsdatabase,query,statsSplunk_SA_CIM5.1.1
82DatabasesDatabasesdatabaseSplunk_SA_CIM5.1.1
83Domain_Analysis.All_DomainsDomain_AnalysisAll_DomainsSA-NetworkProtection6.6.0
84Domain_Analysis.Missing_Extractions_All_DomainsDomain_AnalysisMissing_Extractions_All_DomainsSA-NetworkProtection6.6.0
85Domain_AnalysisDomain_AnalysisSA-NetworkProtection6.6.0
86Email.All_EmailEmailAll_EmailemailSplunk_SA_CIMDS001MAIL-ET01Access|DS001MAIL-ET02Receive|DS001MAIL-ET03Send5.1.1
87Email.DeliveryEmailDeliveryemail,deliverySplunk_SA_CIM5.1.1
88Email.ContentEmailContentemail,contentSplunk_SA_CIM5.1.1
89Email.FilteringEmailFilteringemail,filterSplunk_SA_CIM5.1.1
90EmailEmailemailSplunk_SA_CIMDS001MAIL-ET01Access|DS001MAIL-ET02Receive|DS001MAIL-ET03Send5.1.1
91Endpoint.PortsEndpointPortslistening,portSplunk_SA_CIMDS009EndPointIntel-ET06ListeningPorts5.1.1
92Endpoint.ProcessesEndpointProcessesprocess,reportSplunk_SA_CIMDS009EndPointIntel-ET01ProcessLaunch|DS009EndPointIntel-ET03ProcessLaunchwithCLI|DS009EndPointIntel-ET04ProcessLaunchWithHash5.1.1
93Endpoint.ServicesEndpointServicesservice,reportSplunk_SA_CIMDS009EndPointIntel-ET07Service5.1.1
94Endpoint.FilesystemEndpointFilesystemendpoint,filesystemSplunk_SA_CIMDS009EndPointIntel-ET01ObjectChange5.1.1
95Endpoint.RegistryEndpointRegistryendpoint,registrySplunk_SA_CIMDS009EndPointIntel-ET01ObjectChange5.1.1
96EndpointEndpointlistening,portSplunk_SA_CIM5.1.1
97Event_Signatures.SignaturesEvent_SignaturesSignaturestrack_event_signaturesSplunk_SA_CIM5.1.1
98Event_SignaturesEvent_Signaturestrack_event_signaturesSplunk_SA_CIM5.1.1
99Identity_Management.All_AssetsIdentity_ManagementAll_AssetsSA-IdentityManagementDS008HRMasterData-ET01Asset6.6.0
100Identity_Management.High_Critical_AssetsIdentity_ManagementHigh_Critical_AssetsSA-IdentityManagement6.6.0
101Identity_Management.Expected_AssetsIdentity_ManagementExpected_AssetsSA-IdentityManagement6.6.0
102Identity_Management.Should_Timesync_AssetsIdentity_ManagementShould_Timesync_AssetsSA-IdentityManagement6.6.0
103Identity_Management.Should_Update_AssetsIdentity_ManagementShould_Update_AssetsSA-IdentityManagement6.6.0
104Identity_Management.Requires_AV_AssetsIdentity_ManagementRequires_AV_AssetsSA-IdentityManagement6.6.0
105Identity_Management.All_IdentitiesIdentity_ManagementAll_IdentitiesSA-IdentityManagementDS008HRMasterData-ET01Identity6.6.0
106Identity_Management.High_Critical_IdentitiesIdentity_ManagementHigh_Critical_IdentitiesSA-IdentityManagement6.6.0
107Identity_Management.New_IdentitiesIdentity_ManagementNew_IdentitiesSA-IdentityManagement6.6.0
108Identity_Management.Identities_Expiring_SoonIdentity_ManagementIdentities_Expiring_SoonSA-IdentityManagement6.6.0
109Identity_Management.Expired_IdentitiesIdentity_ManagementExpired_IdentitiesSA-IdentityManagement6.6.0
110Identity_Management.Watchlisted_IdentitiesIdentity_ManagementWatchlisted_IdentitiesSA-IdentityManagement6.6.0
111Identity_Management.Expired_Identity_ActivityIdentity_ManagementExpired_Identity_ActivitySA-IdentityManagementDS008HRMasterData-ET01ExpiredIdentity6.6.0
112Identity_ManagementIdentity_ManagementSA-IdentityManagementDS008HRMasterData-ET01Asset|DS008HRMasterData-ET01Identity|DS008HRMasterData-ET01Joined6.6.0
113Incident_Management.Notable_Events_MetaIncident_ManagementNotable_Events_MetaSA-ThreatIntelligence6.6.0
114Incident_Management.Notable_EventsIncident_ManagementNotable_EventsSA-ThreatIntelligence6.6.0
115Incident_Management.Suppressed_Notable_EventsIncident_ManagementSuppressed_Notable_EventsSA-ThreatIntelligence6.6.0
116Incident_Management.Incident_ReviewIncident_ManagementIncident_ReviewSA-ThreatIntelligence6.6.0
117Incident_Management.Correlation_Search_LookupsIncident_ManagementCorrelation_Search_LookupsSA-ThreatIntelligence6.6.0
118Incident_Management.Correlation_SearchesIncident_ManagementCorrelation_SearchesSA-ThreatIntelligence6.6.0
119Incident_Management.Notable_OwnersIncident_ManagementNotable_OwnersSA-ThreatIntelligence6.6.0
120Incident_Management.Review_StatusesIncident_ManagementReview_StatusesSA-ThreatIntelligence6.6.0
121Incident_Management.Security_DomainsIncident_ManagementSecurity_DomainsSA-ThreatIntelligence6.6.0
122Incident_Management.UrgenciesIncident_ManagementUrgenciesSA-ThreatIntelligence6.6.0
123Incident_Management.Notable_Event_SuppressionsIncident_ManagementNotable_Event_SuppressionsSA-ThreatIntelligence6.6.0
124Incident_Management.Suppression_AuditIncident_ManagementSuppression_AuditSA-ThreatIntelligence6.6.0
125Incident_Management.Suppression_Audit_ExpiredIncident_ManagementSuppression_Audit_ExpiredSA-ThreatIntelligence6.6.0
126Incident_Management.Suppression_EventtypesIncident_ManagementSuppression_EventtypesSA-ThreatIntelligence6.6.0
127Incident_ManagementIncident_ManagementSA-ThreatIntelligence6.6.0
128Interprocess_Messaging.All_MessagingInterprocess_MessagingAll_MessagingmessagingSplunk_SA_CIM5.1.1
129Interprocess_MessagingInterprocess_MessagingmessagingSplunk_SA_CIM5.1.1
130Intrusion_Detection.IDS_AttacksIntrusion_DetectionIDS_Attacksids,attackSplunk_SA_CIMDS012NetworkIntrusionDetection-ET01SigDetection5.1.1
131Intrusion_Detection.Application_IDS_AttacksIntrusion_DetectionApplication_IDS_Attacksids,attackSplunk_SA_CIMDS026WebApplicationFW-ET01General5.1.1
132Intrusion_Detection.Host_IDS_AttacksIntrusion_DetectionHost_IDS_Attacksids,attackSplunk_SA_CIMDS020HostIntrustionDetection-ET01SigDetected5.1.1
133Intrusion_Detection.Network_IDS_AttacksIntrusion_DetectionNetwork_IDS_Attacksids,attackSplunk_SA_CIM5.1.1
134Intrusion_DetectionIntrusion_Detectionids,attackSplunk_SA_CIM5.1.1
135JVM.JVMJVMJVMjvmSplunk_SA_CIM5.1.1
136JVM.ThreadingJVMThreadingjvm,threadingSplunk_SA_CIM5.1.1
137JVM.RuntimeJVMRuntimejvm,runtimeSplunk_SA_CIM5.1.1
138JVM.OSJVMOSjvm,osSplunk_SA_CIM5.1.1
139JVM.CompilationJVMCompilationjvm,compilationSplunk_SA_CIM5.1.1
140JVM.ClassloadingJVMClassloadingjvm,classloadingSplunk_SA_CIM5.1.1
141JVM.MemoryJVMMemoryjvm,memorySplunk_SA_CIM5.1.1
142JVMJVMjvmSplunk_SA_CIM5.1.1
143Malware.Malware_AttacksMalwareMalware_Attacksmalware,attackSplunk_SA_CIMDS004EndPointAntiMalware-ET01SigDetected5.1.1
144Malware.Allowed_MalwareMalwareAllowed_Malwaremalware,attackSplunk_SA_CIM5.1.1
145Malware.Blocked_MalwareMalwareBlocked_Malwaremalware,attackSplunk_SA_CIM5.1.1
146Malware.Deferred_MalwareMalwareDeferred_Malwaremalware,attackSplunk_SA_CIM5.1.1
147Malware.Malware_OperationsMalwareMalware_Operationsmalware,operationsSplunk_SA_CIMDS004EndPointAntiMalware-ET02UpdatedSig|DS004EndPointAntiMalware-ET03UpdatedEng5.1.1
148MalwareMalwaremalware,attackSplunk_SA_CIMDS004EndPointAntiMalware-ET01SigDetected5.1.1
149Network_Resolution.DNSNetwork_ResolutionDNSnetwork,resolution,dnsSplunk_SA_CIMDS002DNS-ET01Query|DS002DNS-ET01QueryRequest|DS002DNS-ET01QueryResponse5.1.1
150Network_ResolutionNetwork_Resolutionnetwork,resolution,dnsSplunk_SA_CIMDS002DNS-ET01Query|DS002DNS-ET01QueryRequest|DS002DNS-ET01QueryResponse5.1.1
151Network_Sessions.All_SessionsNetwork_SessionsAll_Sessionsnetwork,sessionSplunk_SA_CIM5.1.1
152Network_Sessions.Session_StartNetwork_SessionsSession_Startnetwork,session,startSplunk_SA_CIM5.1.1
153Network_Sessions.Session_EndNetwork_SessionsSession_Endnetwork,session,endSplunk_SA_CIM5.1.1
154Network_Sessions.DHCPNetwork_SessionsDHCPnetwork,session,dhcpSplunk_SA_CIMDS025IPAddressAssignment-ET01General5.1.1
155Network_Sessions.VPNNetwork_SessionsVPNnetwork,session,vpnSplunk_SA_CIM5.1.1
156Network_SessionsNetwork_Sessionsnetwork,sessionSplunk_SA_CIMDS025IPAddressAssignment-ET01General5.1.1
157Network_Traffic.All_TrafficNetwork_TrafficAll_Trafficnetwork,communicateSplunk_SA_CIMDS010NetworkCommunication-ET01Traffic|DS010NetworkCommunication-ET01TrafficAppAware|DS010NetworkCommunication-ET03UserAware|DS031ApplicationLoadBalancer-ET01General|DS032DNSGlobalLoadBalancer-ET01General5.1.1
158Network_Traffic.Traffic_By_ActionNetwork_TrafficTraffic_By_Actionnetwork,communicateSplunk_SA_CIM5.1.1
159Network_Traffic.Allowed_TrafficNetwork_TrafficAllowed_Trafficnetwork,communicateSplunk_SA_CIMDS010NetworkCommunication-ET01TrafficAllowed5.1.1
160Network_Traffic.Blocked_TrafficNetwork_TrafficBlocked_Trafficnetwork,communicateSplunk_SA_CIMDS010NetworkCommunication-ET01TrafficBlocked5.1.1
161Network_TrafficNetwork_Trafficnetwork,communicateSplunk_SA_CIMDS010NetworkCommunication-ET01Traffic|DS010NetworkCommunication-ET01TrafficAppAware|DS010NetworkCommunication-ET03UserAware5.1.1
162Performance.All_PerformancePerformanceAll_PerformanceSplunk_SA_CIMDS022HostPerformance-ET01General5.1.1
163Performance.CPUPerformanceCPUperformance,cpuSplunk_SA_CIM5.1.1
164Performance.FacilitiesPerformanceFacilitiesperformance,facilitiesSplunk_SA_CIM5.1.1
165Performance.MemoryPerformanceMemoryperformance,memorySplunk_SA_CIM5.1.1
166Performance.StoragePerformanceStorageperformance,storageSplunk_SA_CIM5.1.1
167Performance.NetworkPerformanceNetworkperformance,networkSplunk_SA_CIM5.1.1
168Performance.OSPerformanceOSperformance,osSplunk_SA_CIM5.1.1
169Performance.TimesyncPerformanceTimesyncperformance,os,time,synchronizeSplunk_SA_CIM5.1.1
170Performance.UptimePerformanceUptimeperformance,os,uptimeSplunk_SA_CIM5.1.1
171PerformancePerformanceSplunk_SA_CIMDS022HostPerformance-ET01General5.1.1
172Risk.All_RiskRiskAll_RiskSA-ThreatIntelligenceDS040RiskModifiers-ET01Risk6.6.0
173RiskRiskSA-ThreatIntelligenceDS040RiskModifiers-ET01Risk6.6.0
174Splunk_Audit.Datamodel_AccelerationSplunk_AuditDatamodel_AccelerationSplunk_SA_CIM5.1.1
175Splunk_Audit.Search_ActivitySplunk_AuditSearch_ActivitySplunk_SA_CIMVendorSpecific-SplunkSearchActivity5.1.1
176Splunk_Audit.Acceleration_JobsSplunk_AuditAcceleration_JobsSplunk_SA_CIM5.1.1
177Splunk_Audit.Adhoc_JobsSplunk_AuditAdhoc_JobsSplunk_SA_CIM5.1.1
178Splunk_Audit.Failed_JobsSplunk_AuditFailed_JobsSplunk_SA_CIM5.1.1
179Splunk_Audit.Realtime_JobsSplunk_AuditRealtime_JobsSplunk_SA_CIM5.1.1
180Splunk_Audit.Scheduled_JobsSplunk_AuditScheduled_JobsSplunk_SA_CIM5.1.1
181Splunk_Audit.Subsearch_JobsSplunk_AuditSubsearch_JobsSplunk_SA_CIM5.1.1
182Splunk_Audit.Scheduler_ActivitySplunk_AuditScheduler_ActivitySplunk_SA_CIM5.1.1
183Splunk_Audit.View_ActivitySplunk_AuditView_ActivitySplunk_SA_CIM5.1.1
184Splunk_Audit.Web_Service_ErrorsSplunk_AuditWeb_Service_ErrorsSplunk_SA_CIM5.1.1
185Splunk_Audit.Modular_ActionsSplunk_AuditModular_ActionsmodactionSplunk_SA_CIM5.1.1
186Splunk_Audit.Modular_Action_InvocationsSplunk_AuditModular_Action_Invocationsmodaction,invocationSplunk_SA_CIM5.1.1
187Splunk_AuditSplunk_AuditSplunk_SA_CIM5.1.1
188Splunk_CIM_Validation.AlertsSplunk_CIM_ValidationAlertsSplunk_SA_CIM5.1.1
189Splunk_CIM_Validation.Application_StateSplunk_CIM_ValidationApplication_StateSplunk_SA_CIM5.1.1
190Splunk_CIM_Validation.Missing_Extractions_PortsSplunk_CIM_ValidationMissing_Extractions_PortsSplunk_SA_CIM5.1.1
191Splunk_CIM_Validation.Missing_Extractions_ProcessesSplunk_CIM_ValidationMissing_Extractions_ProcessesSplunk_SA_CIM5.1.1
192Splunk_CIM_Validation.Missing_Extractions_ServicesSplunk_CIM_ValidationMissing_Extractions_ServicesSplunk_SA_CIM5.1.1
193Splunk_CIM_Validation.AuthenticationSplunk_CIM_ValidationAuthenticationSplunk_SA_CIM5.1.1
194Splunk_CIM_Validation.Missing_Extractions_AuthenticationSplunk_CIM_ValidationMissing_Extractions_AuthenticationSplunk_SA_CIM5.1.1
195Splunk_CIM_Validation.CertificatesSplunk_CIM_ValidationCertificatesSplunk_SA_CIM5.1.1
196Splunk_CIM_Validation.Missing_Extractions_CertificatesSplunk_CIM_ValidationMissing_Extractions_CertificatesSplunk_SA_CIM5.1.1
197Splunk_CIM_Validation.Change_AnalysisSplunk_CIM_ValidationChange_AnalysisSplunk_SA_CIM5.1.1
198Splunk_CIM_Validation.Missing_Extractions_Account_ManagementSplunk_CIM_ValidationMissing_Extractions_Account_ManagementSplunk_SA_CIM5.1.1
199Splunk_CIM_Validation.Missing_Extractions_Endpoint_ChangesSplunk_CIM_ValidationMissing_Extractions_Endpoint_ChangesSplunk_SA_CIM5.1.1
200Splunk_CIM_Validation.Missing_Extractions_Filesystem_ChangesSplunk_CIM_ValidationMissing_Extractions_Filesystem_ChangesSplunk_SA_CIM5.1.1
201Splunk_CIM_Validation.Missing_Extractions_Network_ChangesSplunk_CIM_ValidationMissing_Extractions_Network_ChangesSplunk_SA_CIM5.1.1
202Splunk_CIM_Validation.Missing_Extractions_RestartsSplunk_CIM_ValidationMissing_Extractions_RestartsSplunk_SA_CIM5.1.1
203Splunk_CIM_Validation.Compute_InventorySplunk_CIM_ValidationCompute_InventorySplunk_SA_CIM5.1.1
204Splunk_CIM_Validation.Missing_Extractions_CPUSplunk_CIM_ValidationMissing_Extractions_CPUSplunk_SA_CIM5.1.1
205Splunk_CIM_Validation.Missing_Extractions_MemorySplunk_CIM_ValidationMissing_Extractions_MemorySplunk_SA_CIM5.1.1
206Splunk_CIM_Validation.Missing_Extractions_NetworkSplunk_CIM_ValidationMissing_Extractions_NetworkSplunk_SA_CIM5.1.1
207Splunk_CIM_Validation.Missing_Extractions_StorageSplunk_CIM_ValidationMissing_Extractions_StorageSplunk_SA_CIM5.1.1
208Splunk_CIM_Validation.Missing_Extractions_OSSplunk_CIM_ValidationMissing_Extractions_OSSplunk_SA_CIM5.1.1
209Splunk_CIM_Validation.DatabasesSplunk_CIM_ValidationDatabasesSplunk_SA_CIM5.1.1
210Splunk_CIM_Validation.EmailSplunk_CIM_ValidationEmailSplunk_SA_CIM5.1.1
211Splunk_CIM_Validation.Missing_Extractions_All_EmailSplunk_CIM_ValidationMissing_Extractions_All_EmailSplunk_SA_CIM5.1.1
212Splunk_CIM_Validation.Interprocess_MessagingSplunk_CIM_ValidationInterprocess_MessagingSplunk_SA_CIM5.1.1
213Splunk_CIM_Validation.Intrusion_DetectionSplunk_CIM_ValidationIntrusion_DetectionSplunk_SA_CIM5.1.1
214Splunk_CIM_Validation.Missing_Extractions_IDSSplunk_CIM_ValidationMissing_Extractions_IDSSplunk_SA_CIM5.1.1
215Splunk_CIM_Validation.JVMSplunk_CIM_ValidationJVMSplunk_SA_CIM5.1.1
216Splunk_CIM_Validation.MalwareSplunk_CIM_ValidationMalwareSplunk_SA_CIM5.1.1
217Splunk_CIM_Validation.Missing_Extractions_Malware_AttacksSplunk_CIM_ValidationMissing_Extractions_Malware_AttacksSplunk_SA_CIM5.1.1
218Splunk_CIM_Validation.Missing_Extractions_Malware_OperationsSplunk_CIM_ValidationMissing_Extractions_Malware_OperationsSplunk_SA_CIM5.1.1
219Splunk_CIM_Validation.Network_ResolutionSplunk_CIM_ValidationNetwork_ResolutionSplunk_SA_CIM5.1.1
220Splunk_CIM_Validation.Missing_Extractions_DNSSplunk_CIM_ValidationMissing_Extractions_DNSSplunk_SA_CIM5.1.1
221Splunk_CIM_Validation.Network_SessionsSplunk_CIM_ValidationNetwork_SessionsSplunk_SA_CIM5.1.1
222Splunk_CIM_Validation.Missing_Extractions_Network_SessionsSplunk_CIM_ValidationMissing_Extractions_Network_SessionsSplunk_SA_CIM5.1.1
223Splunk_CIM_Validation.Network_TrafficSplunk_CIM_ValidationNetwork_TrafficSplunk_SA_CIM5.1.1
224Splunk_CIM_Validation.Missing_Extractions_Network_TrafficSplunk_CIM_ValidationMissing_Extractions_Network_TrafficSplunk_SA_CIM5.1.1
225Splunk_CIM_Validation.PerformanceSplunk_CIM_ValidationPerformanceSplunk_SA_CIM5.1.1
226Splunk_CIM_Validation.Missing_Extractions_Perf_CPUSplunk_CIM_ValidationMissing_Extractions_Perf_CPUSplunk_SA_CIM5.1.1
227Splunk_CIM_Validation.Missing_Extractions_Perf_FacilitiesSplunk_CIM_ValidationMissing_Extractions_Perf_FacilitiesSplunk_SA_CIM5.1.1
228Splunk_CIM_Validation.Missing_Extractions_Perf_MemorySplunk_CIM_ValidationMissing_Extractions_Perf_MemorySplunk_SA_CIM5.1.1
229Splunk_CIM_Validation.Missing_Extractions_Perf_StorageSplunk_CIM_ValidationMissing_Extractions_Perf_StorageSplunk_SA_CIM5.1.1
230Splunk_CIM_Validation.Missing_Extractions_Perf_NetworkSplunk_CIM_ValidationMissing_Extractions_Perf_NetworkSplunk_SA_CIM5.1.1
231Splunk_CIM_Validation.Missing_Extractions_Perf_TimesyncSplunk_CIM_ValidationMissing_Extractions_Perf_TimesyncSplunk_SA_CIM5.1.1
232Splunk_CIM_Validation.Missing_Extractions_Perf_UptimeSplunk_CIM_ValidationMissing_Extractions_Perf_UptimeSplunk_SA_CIM5.1.1
233Splunk_CIM_Validation.Splunk_AuditSplunk_CIM_ValidationSplunk_AuditSplunk_SA_CIM5.1.1
234Splunk_CIM_Validation.Ticket_ManagementSplunk_CIM_ValidationTicket_ManagementSplunk_SA_CIM5.1.1
235Splunk_CIM_Validation.Missing_Extractions_All_Ticket_ManagmentSplunk_CIM_ValidationMissing_Extractions_All_Ticket_ManagmentSplunk_SA_CIM5.1.1
236Splunk_CIM_Validation.Missing_Extractions_IncidentSplunk_CIM_ValidationMissing_Extractions_IncidentSplunk_SA_CIM5.1.1
237Splunk_CIM_Validation.Missing_Extractions_ProblemSplunk_CIM_ValidationMissing_Extractions_ProblemSplunk_SA_CIM5.1.1
238Splunk_CIM_Validation.Missing_Extractions_ChangeSplunk_CIM_ValidationMissing_Extractions_ChangeSplunk_SA_CIM5.1.1
239Splunk_CIM_Validation.UpdatesSplunk_CIM_ValidationUpdatesSplunk_SA_CIM5.1.1
240Splunk_CIM_Validation.Missing_Extractions_UpdatesSplunk_CIM_ValidationMissing_Extractions_UpdatesSplunk_SA_CIM5.1.1
241Splunk_CIM_Validation.VulnerabilitiesSplunk_CIM_ValidationVulnerabilitiesSplunk_SA_CIM5.1.1
242Splunk_CIM_Validation.Missing_Extractions_VulnerabilitiesSplunk_CIM_ValidationMissing_Extractions_VulnerabilitiesSplunk_SA_CIM5.1.1
243Splunk_CIM_Validation.WebSplunk_CIM_ValidationWebSplunk_SA_CIM5.1.1
244Splunk_CIM_Validation.Missing_Extractions_WebSplunk_CIM_ValidationMissing_Extractions_WebSplunk_SA_CIM5.1.1
245Splunk_CIM_Validation.Untagged_EventsSplunk_CIM_ValidationUntagged_EventsSplunk_SA_CIM5.1.1
246Splunk_CIM_Validation.Untagged_PortsSplunk_CIM_ValidationUntagged_PortsSplunk_SA_CIM5.1.1
247Splunk_CIM_Validation.Untagged_ProcessesSplunk_CIM_ValidationUntagged_ProcessesSplunk_SA_CIM5.1.1
248Splunk_CIM_Validation.Untagged_ServicesSplunk_CIM_ValidationUntagged_ServicesSplunk_SA_CIM5.1.1
249Splunk_CIM_Validation.Untagged_AuthenticationSplunk_CIM_ValidationUntagged_AuthenticationSplunk_SA_CIM5.1.1
250Splunk_CIM_Validation.Untagged_ChangesSplunk_CIM_ValidationUntagged_ChangesSplunk_SA_CIM5.1.1
251Splunk_CIM_Validation.Untagged_EmailSplunk_CIM_ValidationUntagged_EmailSplunk_SA_CIM5.1.1
252Splunk_CIM_Validation.Untagged_IDSSplunk_CIM_ValidationUntagged_IDSSplunk_SA_CIM5.1.1
253Splunk_CIM_Validation.Untagged_Malware_AttacksSplunk_CIM_ValidationUntagged_Malware_AttacksSplunk_SA_CIM5.1.1
254Splunk_CIM_Validation.Untagged_Network_ResolutionSplunk_CIM_ValidationUntagged_Network_ResolutionSplunk_SA_CIM5.1.1
255Splunk_CIM_Validation.Untagged_Network_SessionsSplunk_CIM_ValidationUntagged_Network_SessionsSplunk_SA_CIM5.1.1
256Splunk_CIM_Validation.Untagged_Network_TrafficSplunk_CIM_ValidationUntagged_Network_TrafficSplunk_SA_CIM5.1.1
257Splunk_CIM_Validation.Untagged_Perf_CPUSplunk_CIM_ValidationUntagged_Perf_CPUSplunk_SA_CIM5.1.1
258Splunk_CIM_Validation.Untagged_FacilitiesSplunk_CIM_ValidationUntagged_FacilitiesSplunk_SA_CIM5.1.1
259Splunk_CIM_Validation.Untagged_MemorySplunk_CIM_ValidationUntagged_MemorySplunk_SA_CIM5.1.1
260Splunk_CIM_Validation.Untagged_StorageSplunk_CIM_ValidationUntagged_StorageSplunk_SA_CIM5.1.1
261Splunk_CIM_Validation.Untagged_NetworkSplunk_CIM_ValidationUntagged_NetworkSplunk_SA_CIM5.1.1
262Splunk_CIM_Validation.Untagged_OSSplunk_CIM_ValidationUntagged_OSSplunk_SA_CIM5.1.1
263Splunk_CIM_Validation.Untagged_UpdatesSplunk_CIM_ValidationUntagged_UpdatesSplunk_SA_CIM5.1.1
264Splunk_CIM_Validation.Untagged_VulnerabilitiesSplunk_CIM_ValidationUntagged_VulnerabilitiesSplunk_SA_CIM5.1.1
265Splunk_CIM_Validation.Untagged_WebSplunk_CIM_ValidationUntagged_WebSplunk_SA_CIM5.1.1
266Splunk_CIM_ValidationSplunk_CIM_ValidationSplunk_SA_CIM5.1.1
267Threat_Intelligence.Threat_ActivityThreat_IntelligenceThreat_ActivityDA-ESS-ThreatIntelligenceDS038ThreatIntel-ET01IOCDetected6.6.0
268Threat_Intelligence.Certificate_IntelligenceThreat_IntelligenceCertificate_IntelligenceDA-ESS-ThreatIntelligence6.6.0
269Threat_Intelligence.Email_IntelligenceThreat_IntelligenceEmail_IntelligenceDA-ESS-ThreatIntelligence6.6.0
270Threat_Intelligence.File_IntelligenceThreat_IntelligenceFile_IntelligenceDA-ESS-ThreatIntelligence6.6.0
271Threat_Intelligence.HTTP_IntelligenceThreat_IntelligenceHTTP_IntelligenceDA-ESS-ThreatIntelligence6.6.0
272Threat_Intelligence.IP_IntelligenceThreat_IntelligenceIP_IntelligenceDA-ESS-ThreatIntelligence6.6.0
273Threat_Intelligence.Process_IntelligenceThreat_IntelligenceProcess_IntelligenceDA-ESS-ThreatIntelligence6.6.0
274Threat_Intelligence.Registry_IntelligenceThreat_IntelligenceRegistry_IntelligenceDA-ESS-ThreatIntelligence6.6.0
275Threat_Intelligence.Service_IntelligenceThreat_IntelligenceService_IntelligenceDA-ESS-ThreatIntelligence6.6.0
276Threat_Intelligence.Threat_Group_IntelligenceThreat_IntelligenceThreat_Group_IntelligenceDA-ESS-ThreatIntelligence6.6.0
277Threat_Intelligence.User_IntelligenceThreat_IntelligenceUser_IntelligenceDA-ESS-ThreatIntelligence6.6.0
278Threat_IntelligenceThreat_IntelligenceDA-ESS-ThreatIntelligenceDS038ThreatIntel-ET01IOCDetected6.6.0
279Ticket_Management.All_Ticket_ManagementTicket_ManagementAll_Ticket_ManagementticketingSplunk_SA_CIMDS013TicketManagement-ET01|DS013TicketManagement-ET02LowLevelEvents5.1.1
280Ticket_Management.ChangeTicket_ManagementChangeticketing,changeSplunk_SA_CIM5.1.1
281Ticket_Management.IncidentTicket_ManagementIncidentticketing,incidentSplunk_SA_CIM5.1.1
282Ticket_Management.ProblemTicket_ManagementProblemticketing,problemSplunk_SA_CIM5.1.1
283Ticket_ManagementTicket_ManagementticketingSplunk_SA_CIMDS013TicketManagement-ET01|DS013TicketManagement-ET02LowLevelEvents5.1.1
284Updates.UpdatesUpdatesUpdatesupdate,statusSplunk_SA_CIM5.1.1
285Updates.Available_UpdatesUpdatesAvailable_Updatesupdate,statusSplunk_SA_CIMDS019PatchManagement-Eligible5.1.1
286Updates.Installed_UpdatesUpdatesInstalled_Updatesupdate,statusSplunk_SA_CIMDS019PatchManagement-Applied5.1.1
287Updates.Restart_Required_UpdatesUpdatesRestart_Required_Updatesupdate,statusSplunk_SA_CIMDS019PatchManagement-Applied5.1.1
288Updates.Update_ErrorsUpdatesUpdate_Errorsupdate,errorSplunk_SA_CIMDS019PatchManagement-Failed5.1.1
289UpdatesUpdatesupdate,statusSplunk_SA_CIMDS019PatchManagement-Applied5.1.1
290Vulnerabilities.VulnerabilitiesVulnerabilitiesVulnerabilitiesvulnerability,reportSplunk_SA_CIMDS018VulnerabilityDetection-ET01SigDetected5.1.1
291Vulnerabilities.High_Critical_VulnerabilitiesVulnerabilitiesHigh_Critical_Vulnerabilitiesvulnerability,reportSplunk_SA_CIM5.1.1
292Vulnerabilities.Medium_VulnerabilitiesVulnerabilitiesMedium_Vulnerabilitiesvulnerability,reportSplunk_SA_CIM5.1.1
293Vulnerabilities.Low_Informational_VulnerabilitiesVulnerabilitiesLow_Informational_Vulnerabilitiesvulnerability,reportSplunk_SA_CIM5.1.1
294VulnerabilitiesVulnerabilitiesvulnerability,reportSplunk_SA_CIMDS018VulnerabilityDetection-ET01SigDetected5.1.1
295Web.WebWebWebwebSplunk_SA_CIMDS005WebProxyRequest-ET01Requested|DS005WebProxyRequest-ET01RequestedWebAppAware5.1.1
296Web.ProxyWebProxyweb,proxySplunk_SA_CIM5.1.1
297Web.StorageWebStorageweb,storageSplunk_SA_CIM5.1.1
298WebWebwebSplunk_SA_CIMDS005WebProxyRequest-ET01Requested|DS005WebProxyRequest-ET01RequestedWebAppAware|DS014WebServer-ET01Access5.1.1