As others have said,
A - Correct
B - Correct
Now for the interesting ones.
C - CIM can create reports, which are a type of saved search, which are knowledge objects. Also, yes it is the knowledge manager's role: "you can use the models to generate reports", from the Knowledge Management docs https://docs.splunk.com/Documentation/Splunk/8.2.1/Knowledge/UnderstandandusetheCommonInformationModel
- Correct
D - Splunk's splexicon for add-on: "A type of app..." and the F2 pdf "The CIM add-on is a search time app..." https://docs.splunk.com/Splexicon:Addon
- Correct
ABCD is correct
A. CIM is a methodology for normalizing data.
The CIM provides a standardized approach to normalizing data into common fields and tags, regardless of the source.
B. CIM can correlate data from different sources.
By normalizing data into a common format, the CIM allows Splunk to correlate events and fields across various data sources.
C. The Knowledge Manager uses the CIM to create knowledge objects.
This statement is incorrect. While the CIM provides a foundation for building knowledge objects, the Knowledge Manager's role is not explicitly tied to the CIM.
D. CIM is an app that can coexist with other apps on a single Splunk deployment.
The CIM is available as a Splunk add-on and can coexist with other apps on the same Splunk deployment.
I think ABC is correct. Yes, CIM add-on is an app that can be downloaded from splunkbase but as for CIM itself, it is a set of data models which you can use during search time
A different perspective but it is A, C and D for me
A - yes
B - no because the CIM is used to normalise, not to correlate
C - yes
D - yes, according to the Splexicon, an add-on is a type of app therefore D is correct
This is a hard understandable and trick question. In my first read I thought it was ABC but after a while and doing some researches I end up with A and B. Here is my explanation:
C - CIM is not a tool to create Knowledge OBjects. Knowledge manager use CIM to have a default start up of Knowledge OBjects.
D - Despite Add-on be a TYPE of APP, add-on is not equal to an app.
"Unlike an Add-on, App caters towards only a single perspective. It is used only for one common goal and it can be used for a specific thing."
https://dev.splunk.com/enterprise/docs/welcome/?_gl=1*1x7ca1c*_ga*MjA0MTE4MDA2OC4xNjQzMDI4MzEx*_gid*OTYwNjk3ODMxLjE2NTEwNjgwMDE.&_ga=2.11612092.960697831.1651068001-2041180068.1643028311#What-is-a-Splunk-app
https://dev.splunk.com/enterprise/docs/welcome/?_gl=1*1x7ca1c*_ga*MjA0MTE4MDA2OC4xNjQzMDI4MzEx*_gid*OTYwNjk3ODMxLjE2NTEwNjgwMDE.&_ga=2.11612092.960697831.1651068001-2041180068.1643028311#What-is-a-Splunk-add-on
Agree with Ajames21 - option D is incorrect because CIM is an add-on, not an app. So correct answer is ABC
See this discussion on the differences between apps and add-ons:
https://www.splunk.com/en_us/blog/tips-and-tricks/what-are-splunk-apps-and-add-ons.html
and this page on the CIM add-on:
https://splunkbase.splunk.com/app/1621/#/details (App Type is listed as Add-on, bottom right corner of Details tab)
Fun2(page 268)
What is the Common Information Model (CIM)?
• The Splunk Common Information Model provides a methodology to
normalize data
• Leverage the CIM when creating field extractions, field aliases,
event types, and tags to ensure:
– Multiple apps can co-exist on a single Splunk deployment
– Object permissions can be set to global for the use of multiple
apps
– Easier and more efficient correlation of data from different
sources and source types
ABC is correct
A - Duh
B - page 268 fundamentals 2
C - reports and dashboards are knowledge objects, https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtocreatereportsanddashboards
D - CIM is an addon not an app, obvious trick wording
https://docs.splunk.com/Documentation/CIM/4.15.0/User/Overview
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
NLotus
Highly Voted 3 years, 4 months agoHudda
Highly Voted 3 years, 6 months agoachalm
3 years agoarvind200
Most Recent 3 days, 18 hours agoawsgeeky
3 weeks, 6 days agovoiddraco
4 months, 2 weeks agoadella1031
5 months, 3 weeks agoANki_24
1 year agoSH_N
1 year, 4 months agoclapillo
1 year, 10 months agocodemk
2 years, 1 month agometromini
2 years, 1 month agoguilhermecervo
2 years, 8 months agoM9201715
3 years, 3 months agoteems5uk
3 years, 4 months agoteems5uk
3 years, 4 months agoAjames21
3 years, 6 months agoIGoddard90
3 years, 9 months ago