Splunk-Apps icon indicating copy to clipboard operation
Splunk-Apps copied to clipboard

CIM datamodel mapping for DHCP missing

Open webcompas opened this issue 2 years ago • 1 comments

Feature request description

Currently the Splunk addon doesn't provide the mapping of DHCP events to the CIM datamodel "Network Sessions".

Proposed solution

The Splunk Common Information Model (CIM) provides a datamodel"Network Sessions" to be used for DHCP events. Therefor the corresponding events need to be tagged with "network", "session" and "dhcp". In addition the fields have to be mapped according to CIM fields.

For details see https://docs.splunk.com/Documentation/CIM/5.1.0/User/NetworkSessions

webcompas avatar Jan 30 '23 15:01 webcompas

:tada: Thanks for opening your first issue here! Welcome to the community!