Exam SPLK-1004 All QuestionsBrowse all questions from this exam
Question 22

Which field is required for an event annotation?

    Correct Answer: B

    The required field for an event annotation is _time. This field is essential for specifying when the event occurred, thereby enabling proper chronological placement in analyses and visualizations.

Discussion
Eddie_examOption: B

Correct answer is B. Only _time is a required field. See https://docs.splunk.com/Documentation/SplunkCloud/latest/Viz/ChartEventAnnotations

DeragOption: B

B. _time is the only field that is required.