nerdexam
Splunk

SPLK-1002 · Question #247

Which of the following data model are included In the Splunk Common Information Model (CIM) add-on? (select all that apply)

The correct answer is A. Alerts B. Email C. Database. The Splunk Common Information Model (CIM) add-on ships with a standardized set of data models to normalize data from disparate sources. These include Alerts, Authentication, Certificates, Change, Databases, Email, Endpoint, Malware, Network Traffic, Vulnerabilities, Web, and…

Using the Common Information Model Add-On

Question

Which of the following data model are included In the Splunk Common Information Model (CIM) add-on? (select all that apply)

Options

  • AAlerts
  • BEmail
  • CDatabase
  • DUser permissions

How the community answered

(39 responses)
  • A
    92% (36)
  • D
    8% (3)

Explanation

The Splunk Common Information Model (CIM) add-on ships with a standardized set of data models to normalize data from disparate sources. These include Alerts, Authentication, Certificates, Change, Databases, Email, Endpoint, Malware, Network Traffic, Vulnerabilities, Web, and others. 'User permissions' (D) is not a data model included in the CIM add-on. The CIM's purpose is to allow searches, reports, and dashboards to work across different data sources by mapping vendor-specific fields to common field names.

Topics

#CIM#Data Models#Splunk CIM Add-on#Common Information Model

Community Discussion

No community discussion yet for this question.

Full SPLK-1002 Practice