CIM & Data Models in Splunk ES

Pune Splunk User Group
Thu, Jun 24, 2021, 6:00 PM (IST)

About this event

Please join us on Thursday, June 24th, 06:00 PM IST for Pune Splunk User Group meetup. Suman & Team is going to talk about the importance of CIM & Data Models in Splunk Enterprise Security. Below the basic agenda of the meetup:

1. What is CIM

2. Use CIM to Normalize data

3. Which data models are part of CIM

4. Demo on CIM validator

5. Demo on CIM tags & Event types

6. How to tune CIM data models to reduce false positives

Please RSVP to block your calendar and receive future updates/Events by Pune Splunk User Group.

Also, join Splunk User group on Slack using splk.it/slack and find us in #splunk-pune-user-group channel for collaborations and Q&A for Pune Splunk User Group.

Speaker

When

Thursday, Jun 24
6:00 PM - 7:30 PM (IST)

Hosts

  • Rohit Joshi

    Rohit Joshi

    TIAA

    Splunk Consultant

  • Gauri Bansode Kulkarni

    Gauri Bansode Kulkarni

    bitsIO

    Splunk Consultant

    See Bio

Organizers