ExamGecko
Question list
Search
Search

Question 150 - SPLK-1002 discussion

Report
Export

Consider the following search:

Index=web sourcetype=access_combined

The log shows several events that share the same JSESSIONID value (SD404K289O2F151). View the events as a group. From the following list, which search groups events by JSESSIONID?

A.
index=web sourcetype=access_combined SD404K289O2F151 I table JSESSIONID
Answers
A.
index=web sourcetype=access_combined SD404K289O2F151 I table JSESSIONID
B.
index=web sourcetype=access_combined JSESSIONID <SD404K289O2F151>
Answers
B.
index=web sourcetype=access_combined JSESSIONID <SD404K289O2F151>
C.
index=web sourcetype=access_combined I highlight JSESSIONID I search SD404K289O2F151
Answers
C.
index=web sourcetype=access_combined I highlight JSESSIONID I search SD404K289O2F151
D.
index-web sourcetype=access_combined I transaction JSESSIONID I search SD404K289O2F151
Answers
D.
index-web sourcetype=access_combined I transaction JSESSIONID I search SD404K289O2F151
Suggested answer: B
asked 23/09/2024
hajar mechrany
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first