Free Resource · Splunk Elite Partner
Data Onboarding Checklist for NERC CIP Environments
A one-page field checklist for onboarding any new data source into a Splunk pipeline that touches BES Cyber Systems. Clean parsing and right-sized volume, with the logging and audit evidence that CIP asks for, built into every stage.
What's inside
Ten stages, from first request to production hand-off, with the NERC CIP control mapped to the step where it applies:
- Source intake · capture source facts and the data owner.
- Scope & classify · define the use case; asset classification (CIP-002).
- Sizing & volume · verify daily volume; model license and storage cost.
- Access & least privilege · need-to-know on data and tooling (CIP-004).
- Change control & baseline · documented change, dev-first, stay inside the ESP (CIP-010, 005/011).
- Source typing: the “Great Eight” · the props.conf settings that get event breaking and timestamps right.
- CIM normalization · naming, certified add-ons, data-model mapping.
- Validation · format, completeness, required security events (CIP-007 R4.1).
- Retention & audit · 90-day retention, version control, historical evidence (CIP-007 R4.3, CIP-010).
- Alerting, monitoring & hand-off · real-time alerts, 15-day review, close the change (CIP-007 R4.2/R4.4).
Go deeper: the data onboarding series
- Data Onboarding Without the Rework: A Field Checklist for Splunk
- The Great Eight: props.conf Settings Every Splunk Source Type Needs
- Onboarding Data Under NERC CIP: Turn Log Hygiene Into Compliance Evidence
Configuration practices per Splunk Lantern. Reference aid only, not legal advice. Validate against your registered entity's compliance program and Regional Entity guidance.

