Every data source in ES must be **CIM-compliant**. This means raw events must be normalized into standard fields defined by the Common Information Model.
For example, firewall logs from different vendors might use `src_ip`, `source`, or `srcaddr` — the CIM maps all of these to the standard field `src`.
The **CIM Validation** dashboard (`SA-CIMValidation`) lets admins verify that each data source correctly populates the expected CIM fields for its data model (e.g., Network_Traffic, Authentication).
| datamodel Authentication search | head 5 | fields action, app, dest, src, user