ExamGecko
Question list
Search
Search

Question 112 - SPLK-1003 discussion

Report
Export

All search-time field extractions should be specified on which Splunk component?

A.
Deployment server
Answers
A.
Deployment server
B.
Universal forwarder
Answers
B.
Universal forwarder
C.
Indexer
Answers
C.
Indexer
D.
Search head
Answers
D.
Search head
Suggested answer: D

Explanation:

Search-time field extractions are the process of extracting fields from events after they are indexed.

Search-time field extractions are specified on the search head, which is the Splunk component that handles searching and reporting. Search-time field extractions are configured in props.conf and transforms.conf files, which are located in the etc/system/local directory on the search head.

Therefore, option D is the correct answer. Reference: Splunk Enterprise Certified Admin | Splunk, [About fields - Splunk Documentation]

asked 23/09/2024
Suneth Jayalath
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first