ExamGecko
Question list
Search
Search

Question 281 - SPLK-1002 discussion

Report
Export

Which of the following can be saved as an event type?

A.

index=server_485 sourcetype=BETA_726 code=917 ['inputlookup append=t servercode.csv]

Answers
A.

index=server_485 sourcetype=BETA_726 code=917 ['inputlookup append=t servercode.csv]

B.

index=server_485 sourcetype=BETA_726 code=917 | stats where code > 200

Answers
B.

index=server_485 sourcetype=BETA_726 code=917 | stats where code > 200

C.

index=server_485 sourcetype=BETA_726 code=917

Answers
C.

index=server_485 sourcetype=BETA_726 code=917

D.

index=server_485 sourcetype=BETA_726 code=917 | stats count by code

Answers
D.

index=server_485 sourcetype=BETA_726 code=917 | stats count by code

Suggested answer: C

Explanation:

Event types in Splunk are saved as static search strings. The example index=server_485 sourcetype=BETA_726 code=917 is a simple search that can be saved as an event type, as it does not contain dynamic processing commands like stats or inputlookup, which are not valid for event types.

Splunk Docs - Event types

asked 18/10/2024
Mohammedsaleh Ibrahim
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first