Splunk CIM (PART-2): How to make data CIM compatible using tags,eventtypes , field extractions
If you want to avail the membership please follow the below link,
https://www.youtube.com/channel/UC3tExxdDT9plEIwKWfoCNNw/join
In this video I have discussed about how to make data CIM compatible using tags,eventtypes , field extractions
Configs used here can be downloaded from the below repo,
https://github.com/siddharthajuprod07/youtube/tree/master/cim_part2