nerdexam
Splunk

SPLK-1002 · Question #110

There are several ways to access the field extractor. Which option automatically identifies data type, source type, and sample event?

The correct answer is B. Fields sidebar > Extract New Field. Accessing the Field Extractor via the Fields sidebar > Extract New Field automatically identifies the data type (e.g., structured vs. unstructured), source type, and provides a pre-selected sample event based on the search you were running. This context-awareness makes it the…

Creating and Managing Fields

Question

There are several ways to access the field extractor. Which option automatically identifies data type, source type, and sample event?

Options

  • AEvent Actions > Extract Fields
  • BFields sidebar > Extract New Field
  • CSettings > Field Extractions > New Field Extraction
  • DSettings > Field Extractions > Open Field Extraction

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    91% (42)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Accessing the Field Extractor via the Fields sidebar > Extract New Field automatically identifies the data type (e.g., structured vs. unstructured), source type, and provides a pre-selected sample event based on the search you were running. This context-awareness makes it the most streamlined entry point for field extraction. Option A (Event Actions > Extract Fields) also launches the FX from an event but may not pre-populate all three attributes as seamlessly. Options C and D (via Settings > Field Extractions) launch the FX in a more manual, configuration-focused mode where you must specify source type and other parameters yourself - they do not automatically identify these details from your current search context.

Topics

#Field Extraction#Splunk Web UI#Field Creation#Source Type Identification

Community Discussion

No community discussion yet for this question.

Full SPLK-1002 Practice