ExamGecko
Question list
Search
Search

Question 4 - SPLK-1003 discussion

Report
Export

What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?

A.
REGEX, DEST. FORMAT
Answers
A.
REGEX, DEST. FORMAT
B.
REGEX. SRC_KEY, FORMAT
Answers
B.
REGEX. SRC_KEY, FORMAT
C.
REGEX, DEST_KEY, FORMAT
Answers
C.
REGEX, DEST_KEY, FORMAT
D.
REGEX, DEST_KEY FORMATTING
Answers
D.
REGEX, DEST_KEY FORMATTING
Suggested answer: C

Explanation:

REGEX = <regular expression>

* Enter a regular expression to operate on your data.

FORMAT = <string>

* NOTE: This option is valid for both index-time and search-time field extraction. Index-time field extraction configuration require the FORMAT settings. The FORMAT settings is optional for searchtime field extraction configurations.

* This setting specifies the format of the event, including any field names or values you want to add.

DEST_KEY = <key>

* NOTE: This setting is only valid for index-time field extractions.

* Specifies where SPLUNK software stores the expanded FORMAT results in accordance with the REGEX match.

asked 23/09/2024
Pedro Faro
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first