A. Parsing Phase
B. Input Phase
C. None of the above
D. Indexing Phase
E. License Metering
A. You can hover your mouse for details like total events, time and date.
B. Timeline shows distribution of events specified in the time range in the form of bars.
C. This is default view and you can't make any changes to it.
D. You can click and drag across the bar for selecting the range.
E. Single click to see the result for particular time period.
A. time
B. _time
C. timestamp
D. EventTime
A. Inclusion is generally better than exclusion.
B. Include as many search terms as possible.
C. Try to specify index values.
D. Never select time range.
E. Try to keep specific search terms.
F. Try to use * with every search term.
G. Select the time range always.
A. When results of a search meet a specifically defined condition
B. When an event in a search matches up with a data model
C. When a trigger action meets the predefined conditions
D. When Splunk encounters a syntax error in a search
A. After saving the report, click Scheduling.
B. After saving the report, click Event Type.
C. After saving the report, click Dashboard Panel.
D. After saving the report, click Schedule.
A. 1 Day
B. 7 Days
C. 10 Minutes
D. 15 Minutes
A. Lookups contain static data available in the index
B. Lookups add more fields to results returned by a search
C. Lookup fields cannot be used in searches
D. Lookups pull data at index time and add them to search results
A. *fail
B. fail*
C. f*il
D. *fail*
A. index=security failure | stats sum as "Event Count"
B. index=security failure | stats count by "Event Count"
C. index=security failure | stats count as "Event Count"
D. index=security failure | stats dc(count) as "Event Count"
A. Use the time range picker to select "Last 24 hours"
B. Use earliest=-1d@d latest=@d
C. Set a real-time search over a 24-hour window
D. Use the time range picket to select "Yesterday"
A. No
B. Yes