Which field is required for an event annotation?

Which field is required for an event annotation?

  1. annotation category
  2. _time Source Reference Answer
  3. eventtype
  4. annotation label

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests knowledge of Splunk event annotation fields, with the common trap being that category or label are optional while _time is mandatory.

In the Splunk SPLK-1004 exam, candidates are asked which field is mandatory for an event annotation. Community consensus and Splunk documentation confirm that _time is the only required field; annotation category and label are optional.

Choosing 'annotation category' or 'annotation label' because those seem essential to an annotation, but Splunk only requires _time; the others are optional metadata.

Community Discussion (3 comments)

ykamalharsha 👍 1 Selected: B
https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Viz/ChartEventAnnotations _time is an mandatory but the annotation category and annotation label is optional
Derag 👍 1
B. _time is the only field that is required.
Eddie_exam 👍 2 Selected: B
Correct answer is B. Only _time is a required field. See https://docs.splunk.com/Documentation/SplunkCloud/latest/Viz/ChartEventAnnotations

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

_time is required because annotations are drawn on the timeline based on timestamp. Without _time, Splunk cannot place the annotation on the event timeline. Official Splunk docs list _time as the only required field; category and label are optional to style/describe the annotation.

Why the Other Options Are Wrong

annotation category is optional and used to define color/grouping. eventtype is a different concept, not required for annotations. annotation label optional display text. They may be used for richer annotations, but not required.

Community Comment Notes

User [1] and [2] cite official Splunk docs confirming _time is mandatory, category/label optional. Votes 100% B. Comment [2] points to SplunkCloud 9.3.2408 docs.

Official Reference

Exam Strategy

Memorize the four annotation fields and their requiredness. On exam day, look for _time as the only must-have; if an option says 'category' or 'label' is required, eliminate it.

Related Analysis

Practice All SPLK-1004 Questions

Access 130 questions with complete answers and detailed explanations.

View Full SPLK-1004 Practice Test →

← Back to SPLK-1004 Study Guide