What does the Splunk Common Information Model (CIM) add-on include? (Choose all that apply.)
What does the Splunk Common Information Model (CIM) add-on include? (Choose all that apply.)
The Splunk Common Information Model (CIM) add-on includes pre-configured data models and fields and event category tags. The CIM add-on provides a set of field names and tags that help standardize data from different sources, enabling easier searching and reporting. Custom visualizations and automatic data model acceleration are not included in the CIM add-on by default.
I think, B & C
see Fundamentals PDF page 273
B & C is correct
D is wrong as per default the datamodels are not accelerated and the cim add-on does not contain visualizations.
B and C (Page 273)Splunk CIM Add-on • Set of 22 pre-configured data models – Fields and event category tags – Least common denominator of a domain of interest • Leverage the CIM so that knowledge objects in multiple apps can co-exist on a single Splunk deployment
P.273 bottom Right: The dat models included in the CIM add-on are configured with data model acceleration turned off. Should be only B I think...
I thought B & D was correct
No data models associated with DM are turned off by default. so D cant be correct
could not find anything on automatic data acceleration but definitely B & C
B & C are correct
Its B & C
I think its B & C according to documentation. "The CIM add-on contains a collection of preconfigured data models that you can apply to your data at search time. Each data model in the CIM consists of a set of field names and tags that define the least common denominator of a domain of interest." https://docs.splunk.com/Documentation/CIM/4.19.0/User/Overview#What_data_models_are_included