Splunk Core Certified User — Question 144
Splunk internal fields contains general information about events and starts from underscore i.e. _ .
Answer options
- A. True
- B. False
Correct answer: A
Explanation
The correct answer is True because Splunk's internal fields indeed begin with an underscore, signifying they hold metadata about events. The option False is incorrect as it contradicts the established naming convention used by Splunk for its internal fields.