Exam SPLK-1001 All QuestionsBrowse all questions from this exam
Question 80

By default, which of the following is a Selected Field?

    Correct Answer: D

    By default, sourcetype is a Selected Field. Selected Fields in Splunk are predefined fields that are available for every event. These default fields include host, source, and sourcetype. Therefore, the correct answer is sourcetype.

Discussion
labarcaremo635Option: D

Answer is D, page 79 in PDF

FlavourOption: D

Selected Fields contain default Fields host,source and sourcetype. D is correct

Iman1367Option: D

D is correct.

robbe_Option: A

The answer should be A. "Action"

emlch

action isn't a selected field, selected fields are by default: host, source and sourcetype. Action might be a interesting field depending or you events.