exam questions

Exam SPLK-1002 All Questions

View all questions & answers for the SPLK-1002 exam

Exam SPLK-1002 topic 1 question 122 discussion

Actual exam question from Splunk's SPLK-1002
Question #: 122
Topic #: 1
[All SPLK-1002 Questions]

Which knowledge object is used to normalize field names to comply with the Splunk Common Information Model (CIM)?

  • A. Event types
  • B. Tags
  • C. Field alias
  • D. Search workflow action
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NastyNutsu
2 weeks, 5 days ago
Alias give you a way to normalize data over multiple sources. You can assign one or more aliases to any extracted field, and apply to fields from a lookup table
upvoted 1 times
...
SCARODJ
9 months, 4 weeks ago
Selected Answer: C
We have "Splunk Enterprise knowledge objects include saved searches, event types, tags, field extractions, lookups, reports, alerts, data models, workflow actions, and fields." to choose from, which leaves `Field aliases` out (Source courtesy of Daniel9527: https://docs.splunk.com/Splexicon:Knowledgeobject) Nevertheless, the only find in page match for "to normalize field names" is: b. Create field aliases to normalize field names More precise source: https://docs.splunk.com/Documentation/CIM/latest/User/UsetheCIMtonormalizedataatsearchtime#b._Create_field_aliases_to_normalize_field_names
upvoted 1 times
SCARODJ
9 months, 4 weeks ago
Field alias is number 5 in the table. Very important to learn by heart: https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Searchtimeoperationssequence
upvoted 1 times
...
...
Daniel9527
11 months, 4 weeks ago
But Alias is not Knowledge object, is it? https://docs.splunk.com/Splexicon:Knowledgeobject
upvoted 1 times
...
aarvee
1 year, 4 months ago
Selected Answer: C
FX, Alias and Lookup. So here it would be option C only. Ref: https://docs.splunk.com/Documentation/CIM/5.1.1/User/UsetheCIMtonormalizedataatsearchtime
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago