Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-1003 Topic 5 Question 116 Discussion

Actual exam question for Splunk's SPLK-1003 exam
Question #: 116
Topic #: 5
[All SPLK-1003 Questions]

In this source definition the MAX_TIMESTAMP_LOOKHEAD is missing. Which value would fit best?

Event example:

Show Suggested Answer Hide Answer
Suggested Answer: D

https://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Configuretimestamprecognition

'Specify how far (how many characters) into an event Splunk software should look for a timestamp.' since TIME_PREFIX = ^ and timestamp is from 0-29 position, so D=30 will pick up the WHOLE timestamp correctly.


Contribute your Thoughts:

Geoffrey
8 days ago
I think the best value would be C) MAX_TIMESTAMP_LOOKAHEAD = 20.
upvoted 0 times
...

Save Cancel