This page is a master list of all CIM compliant event types released with Splunk. This page will always contain the mappings for the latest Splunk app release.
SM20
Authentication
STRUST
Certificates
SM21_LOG
Alerts
SUIM
Change
SM19
Change
ST06
Performance
Memory
Storage
CPU
Network Traffic
ROLE_AUTH
Data Access
SM04
Network Sessions
Performance
SRAL
Alerts
SU01
Authentication
SU53
Data Access
AL08
Network Sessions
RSUSR003
Alerts
RSUSR200
Authentication
DEVACCESS
Data Access
SNOTE
Vulnerabilities
STMS
Updates
SM59_RFCDES
Endpoint
Ports
Processes
STAD
Performance
CPU
Memory
Databases
ATRA_STATE
Data Access
CDPOS
Change
E070
Change
HDB_DBCC_AUDIT
Data Access
USH02
Change
UCON_LOG
Change
RZ10_LOG
Change
HDB_DBCC_USRPRV
Authentication
SCU3
Change
SECPOL_LOG
Change
STATS
Database
Session Info
Lock Info
Performance
Memory
CPU
Network Traffic
GRC_LOGS
Data Access
RSAU_CHECK
Change