List of questions
Related questions
Question 58 - SPLK-1005 discussion
Which of the following methods is valid for creating index-time field extractions?
A.
Use the UI to create a sourcetype, specify the field name and corresponding regular expression with capture statement.
B.
Create a configuration app with the index-time props.conf and/or transfoms. conf, and upload the app via UI.
C.
Use the CU app to define settings in fields.conf, and restart Splunk Cloud.
D.
Use the rex command to extract the desired field, and then save as a calculated field.
Your answer:
0 comments
Sorted by
Leave a comment first