ExamGecko
Question list
Search
Search

List of questions

Search

Question 58 - SPLK-1005 discussion

Report
Export

Which of the following methods is valid for creating index-time field extractions?

A.

Use the UI to create a sourcetype, specify the field name and corresponding regular expression with capture statement.

Answers
A.

Use the UI to create a sourcetype, specify the field name and corresponding regular expression with capture statement.

B.

Create a configuration app with the index-time props.conf and/or transfoms. conf, and upload the app via UI.

Answers
B.

Create a configuration app with the index-time props.conf and/or transfoms. conf, and upload the app via UI.

C.

Use the CU app to define settings in fields.conf, and restart Splunk Cloud.

Answers
C.

Use the CU app to define settings in fields.conf, and restart Splunk Cloud.

D.

Use the rex command to extract the desired field, and then save as a calculated field.

Answers
D.

Use the rex command to extract the desired field, and then save as a calculated field.

Suggested answer: B

Explanation:

The valid method for creating index-time field extractions is to create a configuration app that includes the necessary props.conf and/or transforms.conf configurations. This app can then be uploaded via the UI. Index-time field extractions must be defined in these configuration files to ensure that fields are extracted correctly during indexing.

Splunk Documentation

Reference: Index-time field extractions

asked 10/10/2024
Simon Tam
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first