ExamGecko
Question list
Search
Search

Question 229 - SPLK-1001 discussion

Report
Export

Which Field/Value pair will return only events found in the index named security?

A.
index!=Security
Answers
A.
index!=Security
B.
Index-security
Answers
B.
Index-security
C.
Index=Security
Answers
C.
Index=Security
D.
index=Security
Answers
D.
index=Security
Suggested answer: D

Explanation:

The Kusto Query Language (KQL) is the language you use to query data in Azure Data Explorer [1]. To query for events that are found in the index named security, you would use the following KQL query:

index=Security

This query will return all events that are found in the security index. It is important to note that the "=" operator must be used in order to match the exact index name.

asked 23/09/2024
Mike Schatens
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first