Which Knowledge Object does the Splunk Common Information Model (CIM) use to normalize data, in addition to field aliases, event types, and tags?
- Macros
- Lookups
- Workflow actions
- Field extractions
Answer(s): B,D
Reference:
https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime
Reveal Solution Next Question