SPLK-1002 Exam Question 86
A calculated field is a shortcut for performing repetitive, long, or complex transformations using which of the following commands?
SPLK-1002 Exam Question 87
Consider the following search:
index=web sourcetype=access_corabined
The log shows several events that share the same jsesszonid value (SD462K101O2F267). View the events as a group.
From the following list, which search groups events by jSSESSIONID?
index=web sourcetype=access_corabined
The log shows several events that share the same jsesszonid value (SD462K101O2F267). View the events as a group.
From the following list, which search groups events by jSSESSIONID?
SPLK-1002 Exam Question 88
Calculated fields can be based on which of the following?
SPLK-1002 Exam Question 89
When a search returns __________, you can view the results as a list.
SPLK-1002 Exam Question 90
For the following search, which field populates the x-axis?
index=security sourcetype=linux secure | timechart count by action
index=security sourcetype=linux secure | timechart count by action
