Q: 17
A calculated field may be based on which of the following?
Options
Discussion
Yeah, it's extracted fields. Calculated fields in Splunk use data that's already been pulled out during extraction, then perform operations on those fields. Other things like lookups or inline search fields aren't the direct base for calculated fields. Pretty sure D fits best unless they're trying to trick us.
Pretty standard Splunk question, I’ve seen it on practice exams. The phrase they’re looking for is "extracted fields" since calculated fields need an already-parsed base.
D
Extracted fields for sure. Calculated fields usually take what's already parsed out of the raw events and then do math or transformations on those. Maybe you could stretch the logic on search-generated fields, but D is what they're looking for, I think.
Tough one, honestly. I'd pick extracted fields too but sometimes feels like you could argue for fields created in search if SPL gets involved. Still, D seems to be the main intent here.
Be respectful. No spam.