List of questions
Related questions
Question 68 - SPLK-1005 discussion
A log file is being ingested into Splunk, and a few events have no date stamp. How would Splunk first try to determine the missing date of the events?
A.
Splunk will take the date of a previous event within the log file.
B.
Splunk will use the current system time of the Indexer for the date.
C.
Splunk will use the date of when the file monitor was created.
D.
Splunk will take the date from the file modification time.
Your answer:
0 comments
Sorted by
Leave a comment first