nerdexam
Splunk

SPLK-5001 · Question #86

An analyst discovers she has only raw data from a source. She believes that it could be of great value to future analysis efforts if it were available to existing correlation searches and reports…

The correct answer is A. Common Information Model normalization via a Splunk Add-On. By mapping your raw source fields into the CIM using a dedicated add‑on (or by creating one), you normalize that data into the standard field names and values that Enterprise Security’s correlation searches and reports expect. This makes the new data source immediately usable…

Security Data Onboarding and Normalization

Question

An analyst discovers she has only raw data from a source. She believes that it could be of great value to future analysis efforts if it were available to existing correlation searches and reports. What process should the analyst suggest be performed for that source?

Options

  • ACommon Information Model normalization via a Splunk Add-On.
  • BAsset and Identity evaluation via Splunk Enterprise Security.
  • CData ingestion via Splunk Security Essentials.
  • DData ingest evaluation via Splunk Enterprise.

How the community answered

(46 responses)
  • A
    83% (38)
  • B
    2% (1)
  • C
    11% (5)
  • D
    4% (2)

Explanation

By mapping your raw source fields into the CIM using a dedicated add‑on (or by creating one), you normalize that data into the standard field names and values that Enterprise Security’s correlation searches and reports expect. This makes the new data source immediately usable in existing ES content.

Topics

#CIM normalization#Splunk Add-On#data onboarding#correlation searches

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice