Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-1005 Topic 10 Question 10 Discussion

Actual exam question for Splunk's SPLK-1005 exam
Question #: 10
Topic #: 10
[All SPLK-1005 Questions]

A log file is being ingested into Splunk, and a few events have no date stamp. How would Splunk first try to determine the missing date of the events?

Show Suggested Answer Hide Answer
Suggested Answer: D

When events lack a timestamp, Splunk defaults to using the file modification time, which is accessible metadata for parsing time information if no timestamp is present in the log entry. [Reference: Splunk Docs on timestamp recognition]


Contribute your Thoughts:

Billye
2 days ago
I think the answer is D. Using the file modification time makes the most sense since the log file doesn't have a date stamp. Splunk should grab that metadata from the file itself.
upvoted 0 times
...

Save Cancel