SplunkSplunk
SPLK-1003 · Question #96
SPLK-1003 Question #96: Real Exam Question with Answer & Explanation
The correct answer is D: sourcetype, source, host. https://docs.splunk.com/Documentation/SplunkCloud/8.2.2105/SearchReference/Metadata
Splunk Indexing
Question
When indexing a data source, which fields are considered metadata?
Options
- Asource, host, time
- Btime, sourcetype, source
- Chost, raw, sourcetype
- Dsourcetype, source, host
Explanation
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2105/SearchReference/Metadata
Topics
#indexing metadata#Splunk fields#sourcetype#source#host
Community Discussion
No community discussion yet for this question.