From the course: Splunk Core Certified User (SPLK-1001) Cert Prep

Unlock this course with a free trial

Join today to access over 25,500 courses taught by industry experts.

Using the fields sidebar

Using the fields sidebar

So as we've already discussed, when field discovery feature is active, it's going to discover field value pairs in your events. And these field value pairs that are discovered are going to be shown on the field sidebar, which is highlighted here. Now when you go to the field sidebar, you are going to find fields represented in different ways. The first thing you're going to see here is you find an A close to a field. It just tells you that that field is an alphanumeric field. But you are also going to find situations where you see a hash sign close to a field that denotes the numeric fields. The third one here is a number on the right side of the field. So this number here represents the count of unique values. So in the case of client IP here, we are just saying that this field contains over 100 unique values. Now, we have some exam tips here. The first one reads, in the field sidebar, which character identifies alphanumeric field values? So we've just seen that alphanumeric fields…

Contents