フリー問題

Splunk Core Certified User のフリー問題 10 / 20 問目

問題文

A new analyst asks what a field actually is in the Splunk platform. Which description is correct?

選択肢

  1. A stored copy of part of the event, kept separately from the raw text and updated with it.
  2. A searchable name and value pairing in the event data, which can be referred to by its name in a search.
  3. A label that the platform matches against the event text without regard to where the value appears.
  4. A column that an administrator has to define in advance for every source type before any data from it can be indexed.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。