Final answer:
In Splunk, both A) Macros and C) Calculated fields can contain eval expressions, which are used for creating new fields, calculations, or formatting data.
Step-by-step explanation:
The question asks which knowledge object type can contain an eval expression in the context of Splunk, a platform for searching, monitoring, and analyzing machine-generated data. Among the options provided:
- Macros
- Workflow actions
- Calculated fields
- Field aliases
The correct answer is a) Macros and c) Calculated fields. Eval expressions in Splunk are used to create new fields using existing data, perform calculations, or format data in a certain way. Macros in Splunk can include eval expressions to define more complex search commands that can be reused, and calculated fields can be configured to use eval expressions to calculate their value dynamically based on other field values.