ExamGecko
Question list
Search
Search

Question 216 - SPLK-1001 discussion

Report
Export

What are the two most efficient search filters?

A.
_time and host
Answers
A.
_time and host
B.
_time and index
Answers
B.
_time and index
C.
host and sourcetype
Answers
C.
host and sourcetype
D.
index and sourcetype
Answers
D.
index and sourcetype
Suggested answer: B

Explanation:

This is the correct answer because these two filters can help you limit the amount of data that Splunk retrieves from disk, which is the key to fast searching1.The _time filter allows you to specify a narrow time window for your search, which reduces the number of buckets that Splunk scans2.The index filter allows you to specify which index or indexes contain the data that you want to search, which reduces the number of files that Splunk reads3.


asked 23/09/2024
Tyrome Myatt
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first