Splunk Core Certified User — Question 178
Which of the following is a metadata field assigned to every event in Splunk?
Answer options
- A. host
- B. owner
- C. bytes
- D. action
Correct answer: A
Explanation
The correct answer is 'host' because it is a standard metadata field that Splunk automatically assigns to every event to indicate the source host. The other options, while they may be relevant in different contexts, are not universally assigned to each event in Splunk.