Splunk Core Certified User — Question 66

Which time range picker configuration would return real-time events for the past 30 seconds?

Answer options

Correct answer: C

Explanation

The correct answer is C because it specifically indicates a real-time setting for events that have occurred in the last 30 seconds. Options A and B do not specify a real-time context, while option D is labeled as 'Advanced' and does not inherently imply a real-time event stream.