SPLK-5001 · Question #86
An analyst discovers she has only raw data from a source. She believes that it could be of great value to future analysis efforts if it were available to existing correlation searches and reports…
The correct answer is A. Common Information Model normalization via a Splunk Add-On. By mapping your raw source fields into the CIM using a dedicated add‑on (or by creating one), you normalize that data into the standard field names and values that Enterprise Security’s correlation searches and reports expect. This makes the new data source immediately usable…
Question
An analyst discovers she has only raw data from a source. She believes that it could be of great value to future analysis efforts if it were available to existing correlation searches and reports. What process should the analyst suggest be performed for that source?
Options
- ACommon Information Model normalization via a Splunk Add-On.
- BAsset and Identity evaluation via Splunk Enterprise Security.
- CData ingestion via Splunk Security Essentials.
- DData ingest evaluation via Splunk Enterprise.
How the community answered
(46 responses)- A83% (38)
- B2% (1)
- C11% (5)
- D4% (2)
Explanation
By mapping your raw source fields into the CIM using a dedicated add‑on (or by creating one), you normalize that data into the standard field names and values that Enterprise Security’s correlation searches and reports expect. This makes the new data source immediately usable in existing ES content.
Topics
Community Discussion
No community discussion yet for this question.