Data Requirements
Compliance Essentials 3.0.1 uses Splunk data, CIM data models, KV store collections, lookups, and idx_compliance_results.
Required
- Common Information Model (CIM)
- Framework setup data
- System boundaries
- System boundary framework scope
- System boundary control applicability
- System assets or asset mappings
- Search definitions and linked controls
Monitoring Data
Monitoring searches should use CIM data models where possible. Data models should be accelerated based on customer retention and performance needs.
Common data areas include:
- Authentication
- Change
- Endpoint inventory
- Network traffic and sessions
- Vulnerabilities
- Malware and intrusion detection
- Web activity
Evidence Results
Scheduled compliance searches write evidence run results to:
index=idx_compliance_results
Evidence Run Explorer reads from that index.
Production Checklist
- CIM is installed.
- Required data sources are mapped to CIM.
- Data model acceleration is configured where needed.
- System boundaries and assets are configured.
- Saved searches are linked to controls and enabled for boundaries.
- Thresholds and schedules are configured before searches are enabled.