ExamGecko
Question list
Search
Search

Question 40 - SPLK-1002 discussion

Report
Export

Which of the following searches will return events contains a tag name Privileged?

A.
Tag= Priv
Answers
A.
Tag= Priv
B.
Tag= Pri*
Answers
B.
Tag= Pri*
C.
Tag= Priv*
Answers
C.
Tag= Priv*
D.
Tag= Privileged
Answers
D.
Tag= Privileged
Suggested answer: B

Explanation:

A tag is a descriptive label that you can apply to one or more fields or field values in your events1.You can use tags to simplify your searches by replacing long or complex field names or values with short and simple tags1.To search for events that contain a tag name, you can use the tag keyword followed by an equal sign and the tag name1.You can also use wildcards (*) to match partial tag names1. Therefore, option B is correct because it will return events that contain a tag name that starts with Pri. Options A and D are incorrect because they will only return events that contain an exact tag name match. Option C is incorrect because it will return events that contain a tag name that starts with Priv, not Privileged.

asked 23/09/2024
Ivan Mazala
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first