SPLK-1001 Exam Question 16
How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?
SPLK-1001 Exam Question 17
Which search will return only events containing the word "error" and display the results as a table that includes the fields named action, src, and dest?
SPLK-1001 Exam Question 18
Splunk extracts fields from event data at index time and at search time.
SPLK-1001 Exam Question 19
Log filtering/parsing can be done from _____________.
SPLK-1001 Exam Question 20
Search Assistant is enabled by default in the SPL editor with compact settings.
