Which of the following are functions of the stats command?
A.
count, sum, add
B.
count, sum, less
C.
sum, avg, values
D.
sum, values, table
count, sum, less
Which of the following is a Splunk internal field?
A. _raw
B. host
C. _host
D. index
Which of the following searches will show the number of categoryld used by each host?
A.
Sourcetype=access_* |sum bytes by host
B.
Sourcetype=access_* |stats sum(categoryl
C.
by host C.Sourcetype=access_* |sum(bytes) by host
D.
Sourcetype=access_* |stats sum by host
Sourcetype=access_* |stats sum(categoryl
NOT status = 100:
A. Will display result depending on the data.
B. Will return event where status field exist but value of that field is not 100.
C. Will return event where status field exist but value of that field is not 100 and all events where status field doesn't exist.
Which search matches the events containing the terms "error" and "fail"?
A.
index=security Error Fail
B.
index=security error OR fail
C.
index=security "error failure"
D.
index=security NOT error NOT fail
index=security Error Fail
This function of the stats command allows you to return the sample standard deviation of a field.
A.
stdev
B.
dev
C.
count deviation
D.
by standarddev
stdev
Page 1 out of 41 Pages |