Splunk parte..2

Splunk parte..2

Quiz parte 2 sobre Splunk.

Imagem de perfil user: iago henrique
iago henrique
1

True or False: Once you rename a field, the new field name must be used in the rest of the search string.

FALSE
TRUE
2

At search time, if an event has an equal(=) sign, the data to the left is treated as a ______ and the data to the right is treated as a ______.

field name, value
field name, sourcetype
lookup, sourcetype
lookup, value
3

Which of the following fields are default selected fields?

host, source
host, sourcetype
index
host, source, sourcetype
4

True or False: Fields are knowledge objects.

FALSE
TRUE
5

At search time, _______ extracts fields from raw event data.

fields command
field extractor
field Discovery
6

In the Fields sidebar, Interesting Fields occur in at least ________ of resulting events.

15%
5%
50%
20%
7

To remove fields from a search, you would use the _________ command.

+fields
fields-
fields+
-fields
8

The fields command allows you to do which of the following? Select all that apply.

Exclude fields (fields -), Include fields (fields +)
Exclude fields (fields -), Include fields (fields), Include fields (fields +)
Include fields (fields), Exclude fields (fields -)
Quizur Logo

Siga nossas redes sociais:

Incorporar

Para incorporar este quiz ao seu site copie e cole o código abaixo.