ExamGecko
Question list
Search
Search

Question 7 - SPLK-1002 discussion

Report
Export

When should you use the transaction command instead of the scats command?

A.
When you need to group on multiple values.
Answers
A.
When you need to group on multiple values.
B.
When duration is irrelevant in search results. .
Answers
B.
When duration is irrelevant in search results. .
C.
When you have over 1000 events in a transaction.
Answers
C.
When you have over 1000 events in a transaction.
D.
When you need to group based on start and end constraints.
Answers
D.
When you need to group based on start and end constraints.
Suggested answer: D

Explanation:

The transaction command is used to group events into transactions based on some common characteristics, such as fields, time, or both. The transaction command can also specify start and end constraints for the transactions, such as a field value that indicates the beginning or the end of a transaction. The stats command is used to calculate summary statistics on the events, such as count, sum, average, etc. The stats command cannot group events based on start and end constraints, but only on fields or time buckets. Therefore, the transaction command should be used instead of the stats command when you need to group events based on start and end constraints.

asked 23/09/2024
ACHILLE CARROLL
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first