SPLK-1002 · Question #264
Which of the following is included with the Splunk Common Information Model (CIM) Add-on?
The correct answer is B. A set of pre-configured data models. The Splunk CIM Add-on ships with a collection of pre-built data models (e.g., Network Traffic, Authentication, Malware) that define a normalized field schema. These data models provide a consistent structure so that searches, reports, and apps built on top of the CIM work…
Question
Which of the following is included with the Splunk Common Information Model (CIM) Add-on?
Options
- ASourcetype definitions from the most popular technology vendors.
- BA set of pre-configured data models.
- CScripted inputs to pre-align data with the CIM.
- DDashboards to validate data quality.
How the community answered
(30 responses)- A7% (2)
- B87% (26)
- C3% (1)
- D3% (1)
Explanation
The Splunk CIM Add-on ships with a collection of pre-built data models (e.g., Network Traffic, Authentication, Malware) that define a normalized field schema. These data models provide a consistent structure so that searches, reports, and apps built on top of the CIM work across different data sources. The CIM Add-on does not include sourcetype definitions from vendors, scripted inputs for data alignment, or data-quality dashboards - those come from individual technology-specific add-ons.
Topics
Community Discussion
No community discussion yet for this question.