nerdexam
Splunk

SPLK-3002 · Question #19

Which of the following is a good use case regarding defining entities for a service?

The correct answer is A. Automatically associate entities to services using multiple entity aliases. Define entities before creating services. When you configure a service, you can specify entity matching rules based on entity aliases that automatically add the entities to your service. A is the correct answer because defining entities for a service allows you to automatically…

Data Inputs and Services

Question

Which of the following is a good use case regarding defining entities for a service?

Options

  • AAutomatically associate entities to services using multiple entity aliases.
  • BAll of the entities have the same identifying field name.
  • CBeing able to split a CPU usage KPI by host name.
  • DKPI total values are aggregated from multiple different category values in the source events.

How the community answered

(29 responses)
  • A
    72% (21)
  • B
    3% (1)
  • C
    17% (5)
  • D
    7% (2)

Explanation

Define entities before creating services. When you configure a service, you can specify entity matching rules based on entity aliases that automatically add the entities to your service. A is the correct answer because defining entities for a service allows you to automatically associate entities to services using multiple entity aliases. Entity aliases are alternative names or identifiers for an entity, such as host name, IP address, MAC address, or DNS name. ITSI matches entity aliases to fields in your data sources and assigns entities to services accordingly. This way, you can avoid manually adding entities to each service and ensure that your services reflect the latest changes in your environment.

Topics

#entities#entity aliases#KPI splitting#service design

Community Discussion

No community discussion yet for this question.

Full SPLK-3002 Practice