Question 1
Q1A Security Operations Center (SOC) is onboarding logs from a custom legacy firewall. The raw logs contain the action 'permit' or 'block', but the Splunk Common Information Model (CIM) requires the field 'action' to contain 'allowed' or 'blocked'.
Which configuration method should the engineer use to normalize this data efficiently without altering the raw data?
Show answer & explanation
Correct answer: B
Using a lookup file is the standard and most efficient way to map vendor-specific field values (like 'permit') to CIM-compliant values (like 'allowed') without modifying the underlying raw data (which SEDCMD would do) or creating complex calculated fields.