SPLK-1002 · Question #251
Which of the following can be saved as an event type?
The correct answer is A. index=server_496 sourcetype=BETA_534 code=610. Event types in Splunk can only be saved from searches that are purely event-retrieving - meaning no pipe characters (|), no transforming commands (like stats, chart, table), no subsearches, and no time range modifiers. Option A is a simple, pipe-free search and qualifies…
Question
Which of the following can be saved as an event type?
Options
- Aindex=server_496 sourcetype=BETA_534 code=610
- Bindex=server_49c sourcetype=BETA_534 code=610 | stats count by code
- Cindex=server_496 sourcetype=BETA_534 code=610 | where code > 200
- Dindex=server_496 sourcetype=BETA_534 code=610 [| inputlookup append=t servercode.csv]
How the community answered
(36 responses)- A92% (33)
- B3% (1)
- C6% (2)
Explanation
Event types in Splunk can only be saved from searches that are purely event-retrieving - meaning no pipe characters (|), no transforming commands (like stats, chart, table), no subsearches, and no time range modifiers. Option A is a simple, pipe-free search and qualifies. Option B uses | stats (a transforming command), Option C uses | where (a pipe command), and Option D contains a subsearch ([| inputlookup ...]). All of B, C, and D are disqualified because event types cannot include pipes or subsearches.
Topics
Community Discussion
No community discussion yet for this question.