Splunk Core Certified User — Question 144

Splunk internal fields contains general information about events and starts from underscore i.e. _ .

Answer options

Correct answer: A

Explanation

The correct answer is True because Splunk's internal fields indeed begin with an underscore, signifying they hold metadata about events. The option False is incorrect as it contradicts the established naming convention used by Splunk for its internal fields.