Video

Splunk for Security: Normalisation - Understanding CIM

Episode 3

Play Video about Splunk for Security What is the Common Information Model (CIM) - Episode 3

Video Summary

In the third episode of our series on the Common Information Model (CIM), we explore how to maximise the benefits of CIM by effectively normalising data. The CIM itself is essentially a comprehensive collection of data models that Splunk continuously updates to support consistent data normalisation. Properly mapping all your data to these models enhances search efficiency and ensures that data remains relevant and actionable, particularly in security contexts where swift and accurate responses are crucial.

To normalise your data to CIM, start by downloading and installing the CIM add-on from Splunkbase, then align your data either manually or by using specialised apps and add-ons. The advantages of CIM compliance include improved search acceleration and reduced overhead, leading to faster responses and better security outcomes. However, normalising large data estates can be resource-intensive, so careful planning and regular maintenance of your CIM configurations are essential for ongoing compliance and optimal performance.

Additional Resources

Who are Somerford?

We are a passionate group of people delivering innovation to our customers on their digital transformation journey.

Splunk Edge Hub

Effortlessly streamline the process of inegrating your data with the Splunk Edge Hub

Splunk Security Solutions

Utilise Splunk's suite of security solutions designed to provide uniefied and robust defence against cyber threads.

Get in Touch to Learn More

With specialist knowledge, skills and experience derived from supporting a broad range of FTSE 100, FTSE 250 and smaller companies Somerford Associates have a strong reputation for enabling digital transformation at scale, at pace and in budget.
Scroll to Top