The Common Information Model (CIM) is the foundation of any effective enterprise Splunk security deployment. The architect ensures all ingested data is CIM-compliant so that ES correlation searches, DMA, and tstats work universally across all log sources.
CIM compliance requires correct props.conf and transforms.conf configurations, often packaged in Splunk Technology Add-ons (TAs). The architect manages the TA lifecycle: testing new TA versions in a staging environment before pushing to production via a Deployment Server, ensuring field extractions do not break existing searches.
For custom or proprietary log sources with no existing TA, the architect writes custom field extractions using regex in props.conf or via the Field Extractor in the UI, then maps extracted fields to CIM field names.