Splunk Core Certified User — Question 196
In the Search and Reporting app, which is a default selected field?
Answer options
- A. index
- B. host
- C. _time
- D. action
Correct answer: B
Explanation
The correct answer is B, as 'host' is the default selected field in the Search and Reporting app, allowing users to filter results by the originating host. Options A, C, and D are not default selections, although they can be used in searches, they do not have the same default status as 'host'.