SPLK-2002(205Q) · Question #156
In splunkd. log events written to the _internal index, which field identifies the specific log channel?
The correct answer is D. channel. In the context of splunkd.log events written to the _internal index, the field that identifies the specific log channel is the "channel" field. This information is confirmed by the Splunk Common Information Model (CIM) documentation, where "channel" is listed as a field name…
Question
In splunkd. log events written to the _internal index, which field identifies the specific log channel?
Options
- Acomponent
- Bsource
- Csourcetype
- Dchannel
How the community answered
(46 responses)- A2% (1)
- B4% (2)
- C2% (1)
- D91% (42)
Explanation
In the context of splunkd.log events written to the _internal index, the field that identifies the specific log channel is the "channel" field. This information is confirmed by the Splunk Common Information Model (CIM) documentation, where "channel" is listed as a field name associated with Splunk Audit Logs .
Topics
Community Discussion
No community discussion yet for this question.