Exam SPLK-1001 All QuestionsBrowse all questions from this exam
Question 60

At index time, in which field does Splunk store the timestamp value?

    Correct Answer: B

    Splunk stores the timestamp value in the '_time' field at index time. This field is a standardized field used by Splunk to record the time when an event occurs, which can then be used for time-based searches and analyses.

Discussion
HUGOTEOption: B

is ok b

marianexOption: B

B, page 199