Video

Splunk for Security: Normalisation - CIM Data Models Acceleration

Episode 2

Play Video about Splunk for Security Data Models Acceleration - Episode 2

Video Summary

In the second episode of our series on the Common Information Model (CIM), we explore how to maximise the benefits of CIM by effectively normalising data. The CIM itself is essentially a comprehensive collection of data models that Splunk continually updates to support consistent data normalisation. Properly mapping all your data to these models enhances search efficiency and ensures that data remains relevant and actionable, particularly in security contexts where prompt and accurate responses are crucial.

To normalise your data to CIM, begin by downloading and installing the CIM add-on from Splunkbase, then align your data either manually or using specialised apps and add-ons. The benefits of CIM compliance include improved search acceleration and reduced overhead, leading to faster responses and better security outcomes. However, normalising large data estates can be resource-intensive, so careful planning and regular maintenance of your CIM configurations are essential for ongoing compliance and optimal performance.

Additional Resources

Who are Somerford?

We are a passionate group of people delivering innovation to our customers on their digital transformation journey.

Splunk Edge Hub

Effortlessly streamline the process of inegrating your data with the Splunk Edge Hub

Splunk Security Solutions

Utilise Splunk's suite of security solutions designed to provide uniefied and robust defence against cyber threads.

Get in Touch to Learn More

With specialist knowledge, skills and experience derived from supporting a broad range of FTSE 100, FTSE 250 and smaller companies Somerford Associates have a strong reputation for enabling digital transformation at scale, at pace and in budget.
Scroll to Top