Splunk Enterprise Security Certified Admin — Question 15
Which component normalizes events?
Answer options
- A. SA-CIM.
- B. SA-Notable.
- C. ES application.
- D. Technology add-on.
Correct answer: A
Explanation
The correct answer is A, SA-CIM, as it is specifically designed to normalize events across various data sources. The other options, while related to event management, do not perform the function of normalizing events.