Splunk Core Certified Advanced Power User — Question 26
When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?
Answer options
- A. Slash notation
- B. Regular expression
- C. Irregular expression
- D. Wildcard-only expression
Correct answer: B
Explanation
The correct answer is B, as regular expressions are a powerful tool for matching patterns within data, making them ideal for filtering whitelists and blacklists. Options A and D are too limited in their functionality for complex filtering needs, while C, irregular expression, is not a recognized term in this context.