A. Calculated fields can be used in the search bar.
True. Calculated fields can be referenced in the search bar like any other extracted field1.
B. Calculated fields can be based on an extracted field.
True. Calculated fields can use extracted fields in their calculations1.
C. Calculated fields can only be applied to host and sourcetype.
False. While you can select a host, source, or source type to apply to the calculated field2, it’s not limited to only these options.
D. Calculated fields are shortcuts for performing calculations using the eval command.
True. Calculated fields are indeed used as shortcuts for performing repetitive, long, or complex transformations using the eval command1.
To answer this question you must pay attention at the search time operations sequence:
1. Extractions 2. Aliases 3. Calculated 4. Lookups 5. Event types 6. Tags
A. That's correct
B. Yes, since calculated fields are evaluate after field extractions
D. That's correct since this is the definition of calculated fields
The documentation say:
"Select host, source or sourcetype to apply to the calculated field and specifi the related name", not only host and source, I have my doubts!
I know that F2 says it MUST be based on extracted field, not CAN be based. But in reality it doesn't need to be. "| eval newField = 1" works just fine, no extracted field. So ABD is correct.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
oksey
Highly Voted 3 years, 11 months agosid2051
Highly Voted 3 years, 10 months agokruasan
Most Recent 11 months agoemergency_gouda
2 years agoemlch
2 years, 1 month agoking1993
2 years, 4 months agohuu_nguyen
2 years, 6 months agogabo1969
2 years, 8 months agogabo1969
2 years, 8 months agoM9201715
2 years, 10 months agoRobo187
3 years, 4 months agoNanila
3 years, 4 months agoIxlJustinlxl
3 years, 6 months agoleonmflai4exam
3 years, 7 months ago