field-extraction-and-cim-mapping
Installation
SKILL.md
Field Extraction and CIM Mapping
Produce documentation-backed, evidence-bound guidance for search-time field extraction and CIM normalization. Draft text artifacts only. Never authenticate to, modify, install on, or deploy to a Splunk environment.
Prerequisites
Record or ask for only the missing items material to the requested decision:
- representative sanitized raw events, including meaningful edge cases;
- sourcetype and relevant current
props.conf,transforms.conf, SPL, aliases, calculated fields, lookups, event types, and tags; - desired source fields and their meanings;
- target CIM dataset and installed CIM version or model details;
- Splunk product/version, persistence scope, app context, and deployment topology when configuration or routing depends on them; and
- observed field/search/data-model validation output when diagnosing or claiming validation.