Audit and Compliance App
App Installation and Support
This application requires the Splunk Common Information Model. The Splunk CIM should be configured correctly and your data should be CIM compliant. The Splunk CIM data models should be accelerated.
Please note: This app does not provide normalisation for any existing data or provides CIM compliance for anything you may already be indexing.
For more information on the Splunk CIM please see:
App – https://splunkbase.splunk.com/app/1621/
Docs – https://docs.splunk.com/Documentation/CIM/4.13.0/User/Overview
Splunk Add-ons and CIM – https://docs.splunk.com/Documentation/AddOns/released/Overview/Add-onsandCIM
Please note: This app contains several scheduled searches. Dashboards may not populate immediately following installation.
This application should be installed on Search Heads. It is not required on Splunk Indexers or Splunk Universal and Heavy Forwarders.