Machine Data Insights
Turn raw machine data into validated, deploy-ready content for Splunk® ES & ITSI - faster, with AI-accelerated tooling and repeatable methods.
There’s Gold In That Data!®
The Foundation
CIM normalization aligns security and operational data from every vendor to Splunk’s standard schemas - so one detection, dashboard, or KPI works across all of them, instead of a custom search per technology.
1 · Disparate vendor fields map to common CIM fields
… and the same for status, http_method, uri_path, bytes.
2 · Eventtypes and tags connect those events to the data models
Why It Matters
You can write detections without CIM - most teams have, one search per technology. Normalized data is what lets a single detection, KPI, or dashboard span every vendor, run at data-model speed, and use the content Splunk ships. ITSI KPIs and entity rules want the same thing: consistent fields and identifiers. Miss it and nothing errors - you just pay for coverage one search at a time.
For Splunk ES
For Splunk ITSI
What breaks when you move a detection onto a data model without CIM normalization
Converting a search to run on a data model is where unmapped sourcetypes surface. The data is in Splunk. The search runs clean. It finds nothing - because those events never reached the model it queries. MDI’s CIM Assessment Toolkit (CAT) finds them first, ranked by impact.
You run the client-side tools; the encrypted exchange hands data to MDI; MDI runs the engine.
CIM Assessment Toolkit · Measure What ES Actually Sees
CAT is a free, open-source Splunkbase app that measures CIM (Common Information Model) compliance at the dataset and sourcetype level - not just the data model level - so you find the gaps that silently break Splunk ES correlation searches. Five KPIs, an impact-ranked remediation queue, an 850+ sourcetype inventory reference, and an automated executive Word report. One-time setup - a summary index and a few macros - then CAT scores your whole environment automatically. Splunk Enterprise 9.0+ with Splunk_SA_CIM.
Log Scrubber · There's Gold in That Data!®
Paydirt is a free, open-source tool that scrubs CUI, PII, PHI, and credentials from Splunk or other log data exports so they can be safely shared and analyzed. It runs entirely on your own machine - as a self-contained browser tool or a Python CLI - with no installation and no network calls. Drop a file, get a sanitized version back. CMMC, HIPAA, and GDPR aware.
Encrypted client data transfer - in and out
Client data never moves by email or thumb drive. Every engagement gets its own private, encrypted exchange: clients drop source data into their inbound folder and collect signed, documented deliverables from their outbound folder - and see nothing else.
Normalization Pipeline · Raw Exports In, Deploy-Ready Artifacts Out
Turning Data Into Gold™
Splunk TAs tab - compile, validate, package
Data Refinery is the engine MDI uses to turn machine-data exports into validated, CIM-compliant Splunk Technical Add-ons and Cribl packs. It profiles fields and sample events, classifies each sourcetype against the relevant CIM data models, and generates the Splunk .conf files (props, tags, etc) that normalize vendor fields to CIM - then compiles, validates, and packages the result.
Where an assessment finds the gaps, Data Refinery builds the fix. Every add-on is linted for CIM compliance, scored for deployment readiness, and run through Splunk AppInspect before it ships - so what you receive is ready to deploy, not a starting point someone still has to finish.
Automated CIM Normalization Summary - generated per project
Data Refinery’s CIM-validated artifacts deploy whichever way your environment runs.
props, transforms, eventtypes & tags - normalize vendor fields to CIM at search / index time. Drop-in for Splunk ES.
normalize and reduce in-stream - cut ingest and license cost before data ever lands.
Both paths ship CIM-validated, AppInspect-checked, and fully documented.
MDI delivers CIM normalization, data-volume reduction, and CIM macro & correlation-search optimization - with AI-accelerated tooling that cuts time-to-value and consulting cost.
Scan to explore
Splunk is a trademark of Cisco and/or its affiliates.