C1000-163 · Question #60
What is used to extract fields, define custom properties, categorize events, and define new QID definitions?
The correct answer is B. DSM Editor. DSM Editor (option B) is the correct answer because it is QRadar's dedicated tool for parsing log sources - it handles all four listed functions in one place: extracting fields from raw event data, creating custom event properties, categorizing events into high-level/low-level…
Question
What is used to extract fields, define custom properties, categorize events, and define new QID definitions?
Options
- AWorkspace
- BDSM Editor
- CLog Activity Preview
- DProperty Configuration
How the community answered
(31 responses)- A6% (2)
- B81% (25)
- C3% (1)
- D10% (3)
Explanation
DSM Editor (option B) is the correct answer because it is QRadar's dedicated tool for parsing log sources - it handles all four listed functions in one place: extracting fields from raw event data, creating custom event properties, categorizing events into high-level/low-level categories, and defining new QID (QRadar Identifier) definitions that map events to known signatures.
Why the distractors are wrong:
- A. Workspace - The Workspace is a dashboard for analysts to build and view investigation layouts; it displays data but has no parsing or definition capabilities.
- C. Log Activity Preview - This view lets you monitor and filter incoming events in real time; it's for observation, not for configuring how events are parsed or labeled.
- D. Property Configuration - While this sounds plausible, it refers to a narrower setting for managing individual custom properties, not the all-in-one tool for extraction, categorization, and QID definitions.
Memory tip: Think of DSM as "Define, Structure, Map" - it Defines QIDs, Structures fields and custom properties, and Maps events to categories. If the question mentions any combination of parsing, custom properties, or QIDs, the answer is almost always the DSM Editor.
Topics
Community Discussion
No community discussion yet for this question.