Which search string only returns events from hostWWW3?
Answer(s): B
Splunk extracts fields from event data at index time and at search time.
Answer(s): A
https://docs.splunk.com/Documentation/Splunk/7.2.3/SearchTutorial/Usefieldstosearch
Field values are case sensitive.
Splunk indexes the data on the basis of timestamps.
https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/Aboutdefaultfields