There are several ways to access the field extractor.
Which option automatically identifies the data type, source type, and sample event?
- Event Actions > Extract Fields
- Fields sidebar > Extract New Fields
- Settings > Field Extractions > New Field Extraction
- Settings > Field Extractions > Open Field Extractor
Answer(s): A
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.4/Knowledge/Managesearch- timefieldextractions
Reveal Solution Next Question