Which knowledge Object does the Splunk Common Information Model (CIM) use to normalize dat
a. in addition to field aliases, event types, and tags?
Normalize your data for each of these fields using a combination of field aliases, field extractions, and lookups.
https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime
Currently there are no comments in this discussion, be the first to comment!