SPLK-1002 Exam QuestionsBrowse all questions from this exam

SPLK-1002 Exam - Question 35


Which Knowledge Object does the Splunk Common Information Model (CIM) use to normalize data, in addition to field aliases, event types, and tags?

Show Answer
Correct Answer: BD

The Splunk Common Information Model (CIM) uses lookups and field extractions, in addition to field aliases, event types, and tags, to normalize data. Lookups are used to map values from one field to another, which helps in standardizing data across different events. Field extractions, on the other hand, are used to parse and structure raw event data into fields that provide more meaningful and consistent information. These methods facilitate the normalization of data, making it more CIM-compliant and easier to analyze.

Discussion

17 comments
Sign in to comment
sid2051Option: D
Sep 11, 2020

Lookup is wrong - Field Extraction shld be correct

some_thing
Jun 21, 2021

Lookup correct: https://docs.splunk.com/Documentation/CIM/4.6.0/User/UsetheCIMtonormalizedataatsearchtime This one clearly states Lookups and field extractions.

gabo1969
Dec 3, 2021

I re-view..the correct is only B lookups..

Networkingguy
May 18, 2023

Seems like the answer is BD here, from the above link from some_thing, 5. Make your fields CIM-compliant. Normalize your data via the three methods, Lookup, Field Aliases and Field Extraction.

[Removed]Option: D
Nov 19, 2020

Reference: Fund 2 - P.268: Leverage CIM when creating field extractions, field aliases, event types and tags ... D is the best-fit in the answer set here.

guuillauumeOption: B
Jan 16, 2023

B is the correct answer

test_12_12Option: B
Mar 3, 2023

B - Lookups are a knowledge object; field extractions aren’t

CRYSYS
Mar 27, 2023

Lookups are, by definition, knowledge objects. https://docs.splunk.com/Splexicon:Knowledgeobject

VijayReddy29Options: BD
Mar 16, 2023

B and D. https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime In the above link- Under point 5a. Normalize your data for each of these fields using a combination of field aliases, field extractions, and lookups.

HereToLearnyOption: D
May 25, 2023

The Answer is D. It can not be B because - Sure. Lookups are used to map values from one field to another. They cannot be used to normalize data by extracting the same data from different events and storing it in the same field. For example, a lookup could be used to map the value "John Doe" from the user_name field to the full_name field. This would not normalize the data, as the user_name and full_name fields would still contain different data. Lookups can be used to normalize data in some cases, but they are not the only knowledge object that can be used for this purpose. Field extractions are a more powerful tool for normalizing data, as they can be used to extract data from events and store it in fields.

Doflamingo
Jul 7, 2023

Does this question ask for multiple options? It doesn't say "Choose all that apply" as in the others. If it needs only one, I'd definitely go for D. Field Extraction. If I can choose more than one, I'd go with B and D.

Marianionut123Option: B
Aug 2, 2022

i think is lookup -> B d. Write lookups to add fields and normalize field values https://docs.splunk.com/Documentation/CIM/5.0.1/User/UsetheCIMtonormalizedataatsearchtime

igweifeanyiOptions: BD
Aug 8, 2022

Fund2, page 170;B and D are correct.

lazer23Option: B
Mar 30, 2023

Lookups : Fund 2 PG .277

Harrysa
Apr 10, 2023

If a user wants to convert numeric field values to strings and then sort on those values, they should use the eval command first and then the sort command. The eval command is used to add a new field to the search results that contains the string representation of the numeric field. For example, the following eval command converts the count field to a string: | eval count_str=tostring(count)

Mntman77Options: BD
Jun 12, 2023

B&D: "field aliases, field extractions, and lookups."

Sam1289Option: B
Jun 23, 2023

B is the answer

Dree_DoggOptions: BD
Aug 15, 2023

It's B&D. See splunk doc here: https://docs.splunk.com/Documentation/CIM/4.6.0/User/UsetheCIMtonormalizedataatsearchtime

PrincePazolOptions: BD
Jan 15, 2024

BD is the correct options. Link to the latest docs: https://docs.splunk.com/Documentation/CIM/5.3.1/User/UsetheCIMtonormalizedataatsearchtime

Alexi2415Options: BD
Feb 8, 2024

B, D https://docs.splunk.com/Documentation/CIM/5.3.1/User/UsetheCIMtonormalizedataatsearchtime

a9f89d1Options: BD
Apr 16, 2024

B & D https://docs.splunk.com/Documentation/CIM/4.6.0/User/UsetheCIMtonormalizedataatsearchtime