Document toolboxDocument toolbox

List of CIM-Compliant Event Types

This page is a master list of all CIM compliant event types released with Splunk. This page will always contain the mappings for the latest Splunk app release.

Event Type

CIM Model(s)

Last Updated

Event Type

CIM Model(s)

Last Updated

AL08

  • Network Sessions

7.1.0

ariba_audit_log

  • Authentication

  • Change

  • Data Access

8.1.1

ATRA_STATE

  • Data Access

7.1.0

CDPOS

  • Change

7.1.0

DEVACCESS

  • Data Access

7.1.0

E070

  • Change

7.1.0

GRC_LOGS

  • Data Access

7.1.0

HDB_CERT_LIST

  • Certificates

    • SSL

8.3.0

HDB_DBC_USRPRV

  • Authentication

7.1.0

HDB_DBCC_AUDIT

  • Data Access

7.1.0

ROLE_AUTH

  • Data Access

7.1.0

RSAU_CHECK

  • Change

7.1.0

RSUSR003

  • Alerts

7.1.0

RSUSR200

  • Authentication

7.1.0

RZ10_LOG

  • Change

7.1.0

SCU3

  • Change

7.1.0

SE37_LOG

  • Data Access

7.3.0

SECPOL_LOG

  • Change

7.1.0

SM04

  • Network Sessions

  • Performance

7.1.0

SM19

  • Change

7.1.0

SM20

  • Authentication

7.1.0

SM21_LOG

  • Alerts

7.3.0

SM59_RFCDES

  • Endpoint

    • Ports

    • Processes

7.1.0

SM69

  • Change

7.3.0

SNOTE

  • Vulnerabilities

7.1.0

SRAL

  • Alerts

7.1.0

ST06

  • Performance

    • Memory

    • Storage

    • CPU

  • Network Traffic

7.1.0

STAD

  • Performance

    • Memory

    • CPU

  • Databases

7.1.0

STATS

  • Database

    • Session Info

    • Lock Info

  • Performance

    • Memory

    • CPU

  • Network Traffic

7.1.0

STMS

  • Updates

7.1.0

STMS_TPLOG

  • Change

7.3.0

STRUST

  • Certificates

    • SSL

7.1.0

STRUST_HISTORY

  • Change

8.0.1

SU01

  • Authentication

7.1.0

SU53

  • Data Access

7.1.0

SUIM

  • Change

7.3.0

UCON_LOG

  • Change

7.3.0

USH02

  • Change

7.1.0