ExamGecko
Question list
Search
Search

Question 239 - SPLK-1001 discussion

Report
Export

Which of the following is the appropriately formatted SPL search?

A.
index=security sourcetype=linux secure (invalid OR failed) | stats count as 'Potential Issues'
Answers
A.
index=security sourcetype=linux secure (invalid OR failed) | stats count as 'Potential Issues'
B.
index=security sourcetype=linux secure (invalid OR failed) | stats as 'Potential Issues'
Answers
B.
index=security sourcetype=linux secure (invalid OR failed) | stats as 'Potential Issues'
C.
index---security sourcetype=linux secure (invalid OR failed) | count stats as 'Potential Issues'
Answers
C.
index---security sourcetype=linux secure (invalid OR failed) | count stats as 'Potential Issues'
D.
index---security sourcetype=linux secure (invalid OR failed) | count as 'Potential Issues'
Answers
D.
index---security sourcetype=linux secure (invalid OR failed) | count as 'Potential Issues'
Suggested answer: A

Explanation:

This is the appropriately formatted SPL search because it follows the SPL syntax rules12, such as:

Using the=operator to specify field-value pairs, such asindex=securityandsourcetype=linux.

Using theORoperator to combine multiple values for the same field, such as(invalid OR failed).

Using the|character to separate commands, such asstats count as 'Potential Issues'.

Using theaskeyword to rename fields, such ascount as 'Potential Issues'.

asked 23/09/2024
Hasan Elmas
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first