ExamGecko
Question list
Search
Search

Question 243 - SPLK-1002 discussion

Report
Export

Consider the following search:

index=web sourcetype=access_combined

The log shows several events that share the same JSESSIONID value (SD470K92802F117). View the events as a group.

From the following list, which search groups events by JSESSIONID?

A.
index=web sourcetype=access_combined | highlight JSESSIONID | search SD470K92802F117
Answers
A.
index=web sourcetype=access_combined | highlight JSESSIONID | search SD470K92802F117
B.
index=web sourcetype=access_combined | transaction JSESSIONID | search SD470K92802F117
Answers
B.
index=web sourcetype=access_combined | transaction JSESSIONID | search SD470K92802F117
C.
index=web sourcetype=access_combined SD470K92802F117 | table JSESSIONID
Answers
C.
index=web sourcetype=access_combined SD470K92802F117 | table JSESSIONID
D.
index=web sourcetype=access_combined JSESSIONID <SD470K92802F117>
Answers
D.
index=web sourcetype=access_combined JSESSIONID <SD470K92802F117>
Suggested answer: B

Explanation:

To group events by JSESSIONID, the correct search is index=web sourcetype=access_combined | transaction JSESSIONID | search SD470K92802F117 (Option B). The transaction command groups events that share the same JSESSIONID value, allowing for the analysis of all events associated with a specific session as a single transaction. The subsequent search for SD470K92802F117 filters these grouped transactions to include only those related to the specified session ID.


asked 23/09/2024
Hans Walter Katzengruber
27 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first