SPLK-1004 Exam QuestionsBrowse all questions from this exam

SPLK-1004 Exam - Question 22


Which field is required for an event annotation?

Show Answer
Correct Answer: BD

The required field for an event annotation is _time. This field is essential for specifying when the event occurred, thereby enabling proper chronological placement in analyses and visualizations.

Discussion

2 comments
Sign in to comment
Eddie_examOption: B
Apr 18, 2024

Correct answer is B. Only _time is a required field. See https://docs.splunk.com/Documentation/SplunkCloud/latest/Viz/ChartEventAnnotations

DeragOption: B
Apr 19, 2024

B. _time is the only field that is required.