Skip to main content
Version: 1.3.0

CIM

The Common Information Model (CIM) is a standardized data model developed by Splunk. It provides:

Common Fields:

Field CategoryFieldsDescription
Base Fieldssource, sourcetype, timestamp, host, indexCore fields for event identification and source tracking
Identity Fieldsuser, src_user, dest_userUser identification and authentication tracking
Network Fieldssrc_ip, dest_ip, src_port, dest_portNetwork communication endpoints

Data Models:

Model TypeFieldsPurpose
Authenticationaction, app, status, auth_methodTrack authentication events and access control
Network Trafficbytes, protocol, direction, tcp_flagsMonitor network communications and traffic patterns
Vulnerabilityseverity, signature, vulnerability_idTrack security vulnerabilities and risks
Changes-Track system and configuration changes
Intrusion Detection-Monitor security threats and intrusions

Event Categories:

CategoryEvent TypesDescription
Authenticationsuccess, failure, logoutAuthentication-related events and outcomes
Networkconnection, alert, trafficNetwork activity and communications
Systemchange, status, errorSystem-level events and status changes
Security-Security-related events and alerts