ExamGecko
Question list
Search
Search

Question 228 - SPLK-1001 discussion

Report
Export

Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip

A.
10
Answers
A.
10
B.
50
Answers
B.
50
C.
100
Answers
C.
100
D.
20
Answers
D.
20
Suggested answer: A

Explanation:

The SPL search specified above will return 10 rows of results by default, as the "top" command specifies a limit of 10 results. The query will search for all events in the security index with a sourcetype of linuxsecure that contain either the terms fail* or invalid and will display the top 10 results according to the src_ip field.

asked 23/09/2024
Matthew Sain
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first