ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 50 - SPLK-5001 discussion

Report
Export

After discovering some events that were missed in an initial investigation, an analyst determines this is because some events have an empty src field. Instead, the required data is often captured in another field called machine_name.

What SPL could they use to find all relevant events across either field until the field extraction is fixed?

A.
| eval src = coalesce(src,machine_name)
Answers
A.
| eval src = coalesce(src,machine_name)
B.
| eval src = src + machine_name
Answers
B.
| eval src = src + machine_name
C.
| eval src = src . machine_name
Answers
C.
| eval src = src . machine_name
D.
| eval src = tostring(machine_name)
Answers
D.
| eval src = tostring(machine_name)
Suggested answer: A
asked 23/09/2024
miquel martin leiva
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first