Splunk Core Certified Power User — Question 200
There are several ways to access the field extractor.
Which option automatically identifies the data type, source type, and sample event?
Answer options
- A. Event Actions > Extract Fields
- B. Fields sidebar > Extract New Fields
- C. Settings > Field Extractions > New Field Extraction
- D. Settings > Field Extractions > Open Field Extractor
Correct answer: A
Explanation
Option A is correct because 'Event Actions > Extract Fields' automatically detects the data type and source type while providing a sample event for field extraction. The other options require manual input or do not offer automatic detection of these attributes.