SPLK-1002 Exam Question 76
Given the macro definition below, what should be entered into the Name and Arguments fileds to correctly configured the macro?


SPLK-1002 Exam Question 77
When using timechart, how many fields can be listed after a by clause?
SPLK-1002 Exam Question 78
The eval command 'if' function requires the following three arguments (in order):
SPLK-1002 Exam Question 79
Which of the following statements are true for this search? (Select all that apply.) SEARCH:
sourcetype=access* |fields action productld status
sourcetype=access* |fields action productld status
SPLK-1002 Exam Question 80
The eval command allows you to do which of the following? (Choose all that apply.)
