exam questions

Exam SPLK-1001 All Questions

View all questions & answers for the SPLK-1001 exam

Exam SPLK-1001 topic 1 question 28 discussion

Actual exam question from Splunk's SPLK-1001
Question #: 28
Topic #: 1
[All SPLK-1001 Questions]

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

  • A. host
  • B. index
  • C. source
  • D. sourcetype
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nonee125
Highly Voted 4 years, 6 months ago
B is correct
upvoted 15 times
...
Cyde
Most Recent 6 months ago
B - index (is the correct answer) "By default, host, source, and sourcetype are displayed under Selected Fields"
upvoted 1 times
...
Lonny
1 year ago
B is correct
upvoted 1 times
...
TheRealSplunkie
1 year, 5 months ago
Selected Answer: B
host, source and sourcetype are listed under "Selected Fields" not "interesting fields".
upvoted 3 times
...
Huslayer
1 year, 5 months ago
Selected Answer: B
Index is the correct answer, try it out!!
upvoted 1 times
...
Sunsil
2 years ago
index is the correct answer
upvoted 1 times
...
Steve2610
2 years, 5 months ago
Selected Answer: B
https://docs.splunk.com/Documentation/Splunk/9.0.0/SearchTutorial/Aboutthesearchapp
upvoted 2 times
...
cagdaskarabag
2 years, 7 months ago
Selected Answer: B
index is not preselected that's why it's in interesting fields.
upvoted 2 times
...
[Removed]
2 years, 8 months ago
Selected Answer: B
Host, source, and sourcetype are in the selected field section by default. Which leaves index for the interesting fields section right below on the sidebar.
upvoted 3 times
...
Cheroti
2 years, 9 months ago
Selected Answer: B
host, source & sourcetype are displayed, by default, under Selected Fields
upvoted 1 times
...
rakusu
3 years, 9 months ago
ANSWER IS B
upvoted 3 times
...
marty
3 years, 11 months ago
host, source & sourcetype are displayed, by default, under Selected Fields, so these answers are incorrect. Index is the correct answer, because it's the only one that is left and also because under Interesting Fields, all the fields are displayed that are present in at least 20% of the results. This would be the case for index, because all events are always part of an index. So the correct answer is B
upvoted 2 times
...
SGBEB
4 years ago
It is ACD slide 60 of Splunk Fundamentals 1
upvoted 1 times
...
Nanila
4 years ago
Instead of "Interesting Fields", it should say "Selected Fields"
upvoted 1 times
...
Nanila
4 years ago
This question is confusing.nteresting fields are key-value pairs that Splunk extracts when searching the data. When you dispatch a search, Splunk will try to identify delimiters such as an equal sign or colon and assign the value on the left as the field and the value on the right as the value. It will then take these key-value pairs and list them under interesting fields if that fields is atleast 20% of the search range by default. You can pop open the fields at the bottom of the selection and select any fields that you want at the top and they become selected fields.https://community.splunk.com/t5/Archive/What-is-an-interesting-field/m-p/417956. I think the correct answer is A, C,D
upvoted 1 times
SpTester
3 years, 11 months ago
It would have been. if that is multiple questions. It is a trick question however. And thats is why A,C,D fields are Selected by default. Whereas Index is not and it is located in Interesting fields by default. Hence Correct answer is B
upvoted 2 times
...
...
Oduro
4 years, 2 months ago
SELECTED FIELDS host 2 source 2 sourcetype Answer is B. Index doesn't fall under selected field.
upvoted 3 times
...
sid2051
4 years, 4 months ago
index is correct answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago