ExamGecko
Question list
Search
Search

Question 277 - SPLK-1002 discussion

Report
Export

Which of the following can be saved as an event type?

A.

index=server_48 sourcetype=BETA_881 code=220

Answers
A.

index=server_48 sourcetype=BETA_881 code=220

B.

index=server_48 sourcetype=BETA_881 code=220 | stats count by code

Answers
B.

index=server_48 sourcetype=BETA_881 code=220 | stats count by code

C.

index=server_48 sourcetype=BETA_881 code=220 | inputlookup append=t servercode.csv

Answers
C.

index=server_48 sourcetype=BETA_881 code=220 | inputlookup append=t servercode.csv

D.

index=server_48 sourcetype=BETA_881 code=220 | stats where code > 220

Answers
D.

index=server_48 sourcetype=BETA_881 code=220 | stats where code > 220

Suggested answer: A

Explanation:

An event type is a classification of events based on a search query, which allows for a static set of search criteria. In this case, option A (index=server_48 sourcetype=BETA_881 code=220) represents a simple search without transforming commands (e.g., stats, inputlookup). Event types cannot include transforming commands such as stats or lookup.

Splunk Documentation - Event Types

asked 18/10/2024
Priyantha Perea
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first