ExamGecko
Question list
Search
Search

Question 164 - SPLK-1002 discussion

Report
Export

Which search string would only return results for an event type called success ful_purchases?

A.
tag=success ful_purchases
Answers
A.
tag=success ful_purchases
B.
Event Type:: successful purchases
Answers
B.
Event Type:: successful purchases
C.
successful_purchases
Answers
C.
successful_purchases
D.
event type---success ful_purchases
Answers
D.
event type---success ful_purchases
Suggested answer: C

Explanation:

This is because event types are added to events as a field named eventtype, and you can use this field as a search term to find events that match a specific event type. For example, eventtype=successful_purchases returns all events that have been categorized as successful purchases by the event type definition. The other options are incorrect because they either use a different field name (tag), a different syntax (Event Type:: or event type---), or have a typo (success ful_purchases).You can learn more about how to use event types in searches from the Splunk documentation1.

asked 23/09/2024
Anthony Steele
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first