ExamGecko
Question list
Search
Search

Question 192 - SPLK-1002 discussion

Report
Export

Which of the following objects can a calculated field use as a source?

A.
An alias of a field.
Answers
A.
An alias of a field.
B.
A field added by an automatic lookup.
Answers
B.
A field added by an automatic lookup.
C.
The tag field.
Answers
C.
The tag field.
D.
The eventtype field.
Answers
D.
The eventtype field.
Suggested answer: B

Explanation:

The correct answer is B. A field added by an automatic lookup.

A calculated field is a field that is added to events at search time by using an eval expression. A calculated field can use the values of two or more fields that are already present in the events to perform calculations. A calculated field can use any field as a source, as long as the field is extracted before the calculated field is defined1.

An automatic lookup is a way to enrich events with additional fields from an external source, such as a CSV file or a database. An automatic lookup can add fields to events based on the values of existing fields, such as host, source, sourcetype, or any other extracted field2. An automatic lookup is performed before the calculated fields are defined, so the fields added by the lookup can be used as sources for the calculated fields3.

Therefore, a calculated field can use a field added by an automatic lookup as a source.

About calculated fields

About lookups

Search time processing

asked 23/09/2024
Shaunt Khalatian
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first