Using the Common Information Model Flashcards

1
Q

What is the Common Information Model used for?

A

CIM provides a methodology for normalizing values to a common field name.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Splunk ES relies heavily on CIM compliant data when:

A
  • Searching Data
  • Running Reports
  • Creating Dashboards
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the steps necessary to use CIM with your data?

A
  1. Getting Data In
  2. Examine Data
  3. Tag Events
  4. Verify Tags
  5. Normalize Fields
  6. Validate Against Model
  7. Package as Add-on
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What happens if your data does not have tags required by the CIM data model?

A

You won’t be able to run a pivot (the pivot will return 0 events).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What data models are included within the Splunk CIM Add-On?

A

Alerts
Authentication
Certificates
Change
Data Access
Databases
Data Loss Prevention
Email
Endpoint
Event Signatures
Interprocess Messaging
Intrusion Detection
Inventory
Java Virtual Machines (JVM)
Malware
Network Resolution (DNS)
Network Sessions
Network Traffic
Performance
Splunk Audit Logs
Ticket Management
Updates
Vulnerabilities
Web

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

By default, how is acceleration configured in the Splunk CIM add-on?

A

Turned off.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which Knowledge Objet does Splunk CIM use to normalize data?

A
  • Field Aliases
  • Event Types
  • Tags
  • Field Extractions
  • Lookups
How well did you know this?
1
Not at all
2
3
4
5
Perfectly