Module 7: knowledge objects Flashcards

1
Q

what are knowledge objects?

A

they are tools you use to discover and analyse your data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are data interpretation knowledge objects?

A

Field and field extractions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what are data classification knowledge objects?

A

Event types

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are data enrichment knowledge objects?

A

Lookups and Workflow Actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is data normalisation on Knowledge objects?

A

Tags and field aliases

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what are datasets in knowledge objects?

A

Data Models

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what are the properties of knowledge objects?

A

Shareable
Reusable
Searchable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a knowledge manager?

A
  • They oversee knowledge object creation and usage for a group or deployment
  • Normalise event data
  • creates data models for Pivot users
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what is a recommended naming convention?

A

Group_ObjectType_Description

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what user Role profile can create Private Knowledge objects?

A

User
Power
Admin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

which roles have access to read and write Private knowledge Objects

A
  • read (person who created it and admin)

- write (person who created it and admin)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

where are knowledge objects managed?

A

They are managed in Settings > Knowledge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is Splunk CIM stand for?

A

It is the Splunk Common Information Model

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what is Splunk CIM used for?

A

Normalise data
correlate data from different sources and source types
leverage to create various knowledge objects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly