exam questions

Exam SPLK-1002 All Questions

View all questions & answers for the SPLK-1002 exam

Exam SPLK-1002 topic 1 question 35 discussion

Actual exam question from Splunk's SPLK-1002
Question #: 35
Topic #: 1
[All SPLK-1002 Questions]

Which Knowledge Object does the Splunk Common Information Model (CIM) use to normalize data, in addition to field aliases, event types, and tags?

  • A. Macros
  • B. Lookups
  • C. Workflow actions
  • D. Field extractions
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sid2051
Highly Voted 4 years, 5 months ago
Lookup is wrong - Field Extraction shld be correct
upvoted 17 times
some_thing
3 years, 8 months ago
Lookup correct: https://docs.splunk.com/Documentation/CIM/4.6.0/User/UsetheCIMtonormalizedataatsearchtime This one clearly states Lookups and field extractions.
upvoted 9 times
gabo1969
3 years, 2 months ago
I re-view..the correct is only B lookups..
upvoted 4 times
Networkingguy
1 year, 9 months ago
Seems like the answer is BD here, from the above link from some_thing, 5. Make your fields CIM-compliant. Normalize your data via the three methods, Lookup, Field Aliases and Field Extraction.
upvoted 2 times
...
...
...
...
[Removed]
Highly Voted 4 years, 3 months ago
Reference: Fund 2 - P.268: Leverage CIM when creating field extractions, field aliases, event types and tags ... D is the best-fit in the answer set here.
upvoted 11 times
...
Examfish010
Most Recent 2 weeks, 5 days ago
Selected Answer: BD
"Normalize your data for each of these fields using a combination of field aliases, field extractions, and lookups." from https://docs.splunk.com/Documentation/CIM/4.6.0/User/UsetheCIMtonormalizedataatsearchtime
upvoted 1 times
...
voiddraco
5 months, 2 weeks ago
Answer is D pg 267 F2 Leverage the CIM when creating Field Extractions, Field Aliases, Event Types and Tags. there is no reason for any answers here to be wrong. there's documentation lol. and the actual PDF that can be found on the internet.
upvoted 1 times
...
[Removed]
10 months, 1 week ago
Selected Answer: BD
B & D https://docs.splunk.com/Documentation/CIM/4.6.0/User/UsetheCIMtonormalizedataatsearchtime
upvoted 1 times
...
Alexi2415
1 year ago
B, D https://docs.splunk.com/Documentation/CIM/5.3.1/User/UsetheCIMtonormalizedataatsearchtime
upvoted 1 times
...
PrincePazol
1 year, 1 month ago
Selected Answer: BD
BD is the correct options. Link to the latest docs: https://docs.splunk.com/Documentation/CIM/5.3.1/User/UsetheCIMtonormalizedataatsearchtime
upvoted 1 times
...
Dree_Dogg
1 year, 6 months ago
Selected Answer: BD
It's B&D. See splunk doc here: https://docs.splunk.com/Documentation/CIM/4.6.0/User/UsetheCIMtonormalizedataatsearchtime
upvoted 1 times
...
Doflamingo
1 year, 7 months ago
Does this question ask for multiple options? It doesn't say "Choose all that apply" as in the others. If it needs only one, I'd definitely go for D. Field Extraction. If I can choose more than one, I'd go with B and D.
upvoted 3 times
...
Sam1289
1 year, 8 months ago
Selected Answer: B
B is the answer
upvoted 1 times
...
Mntman77
1 year, 8 months ago
B&D: "field aliases, field extractions, and lookups."
upvoted 1 times
...
HereToLearny
1 year, 9 months ago
Selected Answer: D
The Answer is D. It can not be B because - Sure. Lookups are used to map values from one field to another. They cannot be used to normalize data by extracting the same data from different events and storing it in the same field. For example, a lookup could be used to map the value "John Doe" from the user_name field to the full_name field. This would not normalize the data, as the user_name and full_name fields would still contain different data. Lookups can be used to normalize data in some cases, but they are not the only knowledge object that can be used for this purpose. Field extractions are a more powerful tool for normalizing data, as they can be used to extract data from events and store it in fields.
upvoted 3 times
...
Harrysa
1 year, 10 months ago
If a user wants to convert numeric field values to strings and then sort on those values, they should use the eval command first and then the sort command. The eval command is used to add a new field to the search results that contains the string representation of the numeric field. For example, the following eval command converts the count field to a string: | eval count_str=tostring(count)
upvoted 1 times
...
lazer23
1 year, 11 months ago
Lookups : Fund 2 PG .277
upvoted 1 times
...
VijayReddy29
1 year, 11 months ago
Selected Answer: BD
B and D. https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime In the above link- Under point 5a. Normalize your data for each of these fields using a combination of field aliases, field extractions, and lookups.
upvoted 3 times
...
test_12_12
1 year, 11 months ago
B - Lookups are a knowledge object; field extractions aren’t
upvoted 3 times
CRYSYS
1 year, 11 months ago
Lookups are, by definition, knowledge objects. https://docs.splunk.com/Splexicon:Knowledgeobject
upvoted 1 times
...
...
guuillauume
2 years, 1 month ago
Selected Answer: B
B is the correct answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago