問題文
A new analyst asks what a field actually is in the Splunk platform. Which description is correct?
選択肢
- A stored copy of part of the event, kept separately from the raw text and updated with it.
- A searchable name and value pairing in the event data, which can be referred to by its name in a search.
- A label that the platform matches against the event text without regard to where the value appears.
- A column that an administrator has to define in advance for every source type before any data from it can be indexed.