Field Extractor (FX) の正規表現モードはどのような場合に使用する必要がありますか? (該当するものをすべて選択)
正解:C,D
The regular expression mode of Field Extractor (FX) should be used for data with multiple, different characters separating fields or for unstructured dat a. The regular expression mode allows you to select a sample event and highlight the fields that you want to extract, and the field extractor generates a regular expression that matches similar events and extracts the fields from them. Reference See Build field extractions with the field extractor - Splunk Documentation and Field Extractor: Select Method step - Splunk Documentation.