Which knowledge Object does the Splunk Common Information Model (CIM) use to normalize data. in addition to field aliases, event types, and tags?

Posted by: Pdfprep Category: SPLK-1002 Tags: , ,

Which knowledge Object does the Splunk Common Information Model (CIM) use to normalize data. in addition to field aliases, event types, and tags?
A . Macros
B . Lookups
C . Workflow actions
D . Field extractions

Answer: B

Explanation:

Normalize your data for each of these fields using a combination of field aliases, field extractions, and lookups.

https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsear chtime

Leave a Reply

Your email address will not be published.