SPLK-1001 Exam Question 116
At index time, in which field does Splunk store the timestamp value?
SPLK-1001 Exam Question 117
When looking at a statistics table, what is one way to drill down to see the underlying events?
SPLK-1001 Exam Question 118
When is the pipe character, I, used in search strings?
SPLK-1001 Exam Question 119
A field exists in search results, but isn't being displayed in the fields sidebar. How can it be added to the fields sidebar?
SPLK-1001 Exam Question 120
Which search matches the events containing the terms "error" and "fail"?
