List of questions
Related questions
Question 44 - SPLK-1004 discussion
A report named 'Linux logins' populates a summary index with the search string sourcetype=linux_secure| sitop src_ip user. Which of the following correctly searches against the summary index for this data?
A.
index=summary sourcetype='linux_secure' | top src_ip user
B.
index=summary search_name='Linux logins' | top src_ip user
C.
index=summary search_name='Linux logins' | stats count by src_ip user
D.
index=summary sourcetype='linux_secure' | stats count by src_ip user
Your answer:
0 comments
Sorted by
Leave a comment first