nerdexam
Splunk

SPLK-1002 · Question #15

A calculated field maybe based on which of the following?

The correct answer is B. Extracted fields. Calculated fields must be based on already-extracted fields. Since a calculated field is essentially a saved eval expression applied at search time, the eval expression can only reference fields that already exist in the event - i.e., fields that have been extracted. Lookup…

Creating Field Aliases and Calculated Fields

Question

A calculated field maybe based on which of the following?

Options

  • ALookup tables
  • BExtracted fields
  • CRegular expressions
  • DFields generated within a search string

How the community answered

(16 responses)
  • B
    88% (14)
  • C
    6% (1)
  • D
    6% (1)

Explanation

Calculated fields must be based on already-extracted fields. Since a calculated field is essentially a saved eval expression applied at search time, the eval expression can only reference fields that already exist in the event - i.e., fields that have been extracted. Lookup tables (A) are a separate enrichment mechanism. Regular expressions (C) are used for field extractions, not as the input to calculated fields. Fields generated within a search string (D) are transient and not available to calculated field definitions, which are applied before a user's search pipeline runs.

Topics

#Calculated Fields#Field Extraction#Data Manipulation

Community Discussion

No community discussion yet for this question.

Full SPLK-1002 Practice