フリー問題

Splunk Certified Cybersecurity Defense Engineer のフリー問題 1 / 20 問目

問題文

A team receives web proxy logs from two different vendors through the same syslog collector. Both currently arrive with the same source type, and the field layout differs between them. What is the effect of leaving them under one source type, and what should the engineer do about it?

選択肢

  1. Splunk detects the layout of each individual event and applies the matching rules automatically, so a shared source type is harmless; the engineer only needs to confirm that both vendors are in the same index.
  2. Source types only affect how events are displayed in the search results list, so the layouts are parsed correctly either way; the engineer should leave the configuration alone and filter on the host field for each layout instead.
  3. The two layouts will be merged into a single normalized layout because they share a source type, so the engineer only has to add a search-time field alias that maps the merged layout onto the Common Information Model instead of separating the parsing rules at index time.
  4. One source type carries one set of parsing rules, so a single set of line-breaking, timestamp, and extraction rules is applied to both layouts; the engineer should split them into separate source types so each gets its own rules, which keeps each vendor's parsing settings independent.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。