Splunk Core Certified User — Question 68

Which statement is true about Splunk alerts?

Answer options

Correct answer: A

Explanation

The correct answer is A because Splunk alerts can be configured to trigger based on searches that run either on a scheduled basis or in real-time. Option B is incorrect as alerts can trigger various types of notifications, not just email. Option C is misleading because while cron can be used for scheduling, it is not a requirement for Splunk alerts, and option D is false since alerts can be based on both real-time and scheduled searches.