QuestionQ74
Creating and Managing FieldsWhat does Splunk recommend when working with the Field Extractor and regex?
- A Use the Field Extractor on its own, without manually entering regex.
- B Use a macro containing the erex command.
- C Use the Regular Expression method of the Field Extractor whenever possible.
- D Use the Field Extractor to generate initial regex, then edit for best performance and accuracy.
Community Discussion