Splunk Core Certified Power User — Question 36
What are the two parts of a root event dataset?
Answer options
- A. Fields and variables.
- B. Fields and attributes.
- C. Constraints and fields.
- D. Constraints and lookups.
Correct answer: C
Explanation
The correct answer is C, as a root event dataset is composed of constraints that define the data and fields that hold the actual values. The other options do not accurately represent the two necessary components of such a dataset.