Fields Flashcards

1
Q

What are selected fields?

A

The fields of upmost importance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 3 default fields?

A

Host, Source and SourceType

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the criteria for ‘Interesting Fields’ and where do they sit?

A

Interesting fields are fields that have values in at least 20% of the events
They sit underneath he selected fields

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What search does it perform when you click on field? what type of data does it return?

A

A transforming search

Shows results as statistical data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What default data does a transforming search show?

A

Values,
A count of values
A list of the percentage of events the values shows up in

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What operators can be used with numerical or string values?

A

=

!=

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What operators can be used for fields ONLY with numerical values?

A

> =
<
<=

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

how would add multiple boolean to a search?

A

NOT (host=mail* OR host=www*)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Fill in the blanks

___ is better than ___

A

Inclusion is better than exclusion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the time operators?

A
S Seconds
M Minutes
H Hours
D days
W Weeks
Mon Month
Y Year
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 2 types of date ranges? give an example for each

A

Relative
earliest=-2h latest=-1hr
Absolute
earliest=04/20/2017:12:00:00

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a key advantage of using indexes

A

Way to filter Events Early

How well did you know this?
1
Not at all
2
3
4
5
Perfectly