SPLK-1002 Exam QuestionsBrowse all questions from this exam

SPLK-1002 Exam - Question 122


Which knowledge object is used to normalize field names to comply with the Splunk Common Information Model (CIM)?

Show Answer
Correct Answer: C

The correct knowledge object used to normalize field names to comply with the Splunk Common Information Model (CIM) is a 'Field alias'. A field alias allows you to map field names to other names to ensure consistent naming conventions, which is essential for the normalization process in CIM.

Discussion

3 comments
Sign in to comment
aarveeOption: C
Aug 18, 2023

FX, Alias and Lookup. So here it would be option C only. Ref: https://docs.splunk.com/Documentation/CIM/5.1.1/User/UsetheCIMtonormalizedataatsearchtime

Daniel9527Option: C
Dec 31, 2023

But Alias is not Knowledge object, is it? https://docs.splunk.com/Splexicon:Knowledgeobject

SCARODJOption: C
Feb 28, 2024

We have "Splunk Enterprise knowledge objects include saved searches, event types, tags, field extractions, lookups, reports, alerts, data models, workflow actions, and fields." to choose from, which leaves `Field aliases` out (Source courtesy of Daniel9527: https://docs.splunk.com/Splexicon:Knowledgeobject) Nevertheless, the only find in page match for "to normalize field names" is: b. Create field aliases to normalize field names More precise source: https://docs.splunk.com/Documentation/CIM/latest/User/UsetheCIMtonormalizedataatsearchtime#b._Create_field_aliases_to_normalize_field_names

SCARODJ
Feb 28, 2024

Field alias is number 5 in the table. Very important to learn by heart: https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Searchtimeoperationssequence