splunk-cim-data-model

Render CIM data-model acceleration configurations and population audits for Splunk.

36|7|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-cim-data-model
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: splunk-cim-data-model
Source: https://github.com/chambear2809/splunk-cisco-skills/tree/main/skills/splunk-cim-data-model
Command: npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-cim-data-model

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

Render, preflight, and validate CIM data-model management assets to safely configure per-model acceleration, backfills, and population audits without altering the shipped CIM content.

Core Features & Use Cases

  • Renders per-model acceleration overrides into a dedicated app local/ directory for isolation from Splunk_SA_CIM/default files.
  • Provides an end-to-end workflow (render, apply, rebuild, status, audit) with validation and safeguards to support Enterprise Security and ITSI readiness.
  • Supplies ready-to-run scripts (apply.sh, rebuild.sh, status.sh, audit.sh) to manage acceleration lifecycles and CIM population checks.

Quick Start

Render CIM data-model assets for the selected models with acceleration enabled using a 7-day summary range.

Frequently Asked Questions about splunk-cim-data-model

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I safely configure CIM data-model acceleration without modifying shipped Splunk defaults?

To safely configure CIM data-model acceleration without modifying defaults, render per-model acceleration overrides into a dedicated local app directory. This isolates your configurations from Splunk_SA_CIM default files, ensuring safe model-level performance tuning.

Can I run CIM population audits and acceleration lifecycle management on clustered search heads?

Yes, you can run CIM population audits and acceleration management on clustered search heads. The workflow supports enterprise Splunk deployments across single or clustered search heads, including Enterprise Security and ITSI readiness workflows.

What is the best way to rebuild and check the status of accelerated CIM data models?

The best way to rebuild and check accelerated CIM data models is using ready-to-run scripts. Execute rebuild.sh to rebuild acceleration and status.sh to verify acceleration status, both providing built-in validation and safeguards for safe operation.

How do I preflight and validate CIM data-model acceleration configurations before applying them?

Preflight and validate CIM data-model acceleration configurations by rendering the assets first. The workflow renders per-model overrides, validates configurations, and provides apply.sh to safely apply changes only after validation checks pass.

Does this approach support Enterprise Security and ITSI readiness workflows for Splunk?

Yes, this approach fully supports Enterprise Security and ITSI readiness workflows for Splunk. It provides an end-to-end workflow with render, apply, rebuild, status, and audit scripts to validate CIM population and acceleration for ES and ITSI readiness.

Why do I need a dedicated app for CIM data-model acceleration overrides?

A dedicated app for CIM data-model acceleration overrides provides isolation from Splunk_SA_CIM default files. This separation ensures that shipped CIM content remains unaltered, enabling safe backfills, population audits, and model-level performance tuning.