Exam SPLK-1001 All QuestionsBrowse all questions from this exam
Question 199

Which Field/Value pair will return only events found in the index named security?

    Correct Answer: B

    The field 'index' is case-sensitive in Splunk, and the index names are typically lowercase. Therefore, to return only events found in the index named 'security', the correct field/value pair would be 'index=security'.

Discussion
Alex_Cyber_SecOption: B

Answer is B. The key is index case sensitive.