Splunk - Using Fields Quiz with Complete Answers
True or False: Fields are knowledge objects.
(A) False (B) True ✔✔(B) True
At search time, if an event has an equal(=) sign, the data to the left is treated as a ______ and the data to the right is treated as a ______.
(A) field name, value (B) field name, sourcetype (C) lookup, sourcetype (D) lookup, value ✔✔(A) field name, value
The fields command allows you to do which of the following? Select all that apply.
(A) Exclude fields (fields -)
- / 1