ExamGecko
Question list
Search
Search

Question 228 - SPLK-1002 discussion

Report
Export

Consider the the following search run over a time range of last 7 days:

index=web sourcetype=access_conbined | timechart avg(bytes) by product_nane

Which option is used to change the default time span so that results are grouped into 12 hour intervals?

A.
span=12h
Answers
A.
span=12h
B.
timespan=12h
Answers
B.
timespan=12h
C.
span=12
Answers
C.
span=12
D.
timespan=12
Answers
D.
timespan=12
Suggested answer: A

Explanation:

The span option is used to specify the time span for the timechart command. The span value can be a number followed by a time unit, such as h for hour, d for day, w for week, etc. The span value determines how the data is grouped into time buckets. For example, span=12h means that the data is grouped into 12-hour intervals.The timespan option is not a valid option for the timechart command2

1: Splunk Core Certified Power User Track, page 9.2: Splunk Documentation, timechart command.

asked 23/09/2024
saiming wong
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first