Machine Data Insights
Turn raw machine data into validated, deploy-ready content for Splunk® ES & ITSI - faster, with AI-accelerated tooling and repeatable methods.
There’s Gold In That Data!®
The Foundation
CIM normalization aligns security and operational data from every vendor to Splunk’s standard schemas - so one detection, dashboard, or KPI works across all of them, instead of a custom search per technology.
Why It Matters
You can write detections without CIM - most teams have, one search per technology. Normalized data is what lets a single detection, KPI, or dashboard span every vendor, run at data-model speed, and use the content Splunk ships. ITSI KPIs and entity rules want the same thing: consistent fields and identifiers. Miss it and nothing errors - you just pay for coverage one search at a time.
For Splunk ES
For Splunk ITSI
What breaks when you move a detection onto a data model without CIM normalization
Converting a search to run on a data model is where unmapped sourcetypes surface. The data is in Splunk. The search runs clean. It finds nothing - because those events never reached the model it queries. MDI’s CIM Assessment Toolkit (CAT) finds them first, ranked by impact.
You run the client-side tools; the encrypted exchange hands data to MDI; MDI runs the engine.
CIM Assessment Toolkit
Free, open-source app that scores CIM compliance by dataset and sourcetype - exposing the gaps that break Splunk ES correlation searches.
Log Scrubber
Free, open-source scrubber for CUI, PII, PHI & credentials. Runs fully on your machine - no install, no network calls. CMMC, HIPAA & GDPR aware.
Encrypted Data Transfer
A private, encrypted cloud channel per engagement - clients upload source data, collect signed deliverables. Isolated, encrypted, fully logged.
Normalization Engine
The MDI engine that builds the fix an assessment finds: validated, CIM-compliant Splunk TAs and Cribl packs - AppInspect-checked and deploy-ready.
Data Refinery’s CIM-validated artifacts deploy whichever way your environment runs.
props, transforms, eventtypes & tags - normalize vendor fields to CIM at search / index time. Drop-in for Splunk ES.
normalize and reduce in-stream - cut ingest and license cost before data ever lands.
Both paths ship CIM-validated, AppInspect-checked, and fully documented.
MDI delivers CIM normalization, data-volume reduction, and CIM macro & correlation-search optimization - with AI-accelerated tooling that cuts time-to-value and consulting cost.
Scan to explore
Splunk is a trademark of Cisco and/or its affiliates.