Fields Flashcards
What are selected fields?
The fields of upmost importance
What are the 3 default fields?
Host, Source and SourceType
What is the criteria for ‘Interesting Fields’ and where do they sit?
Interesting fields are fields that have values in at least 20% of the events
They sit underneath he selected fields
What search does it perform when you click on field? what type of data does it return?
A transforming search
Shows results as statistical data
What default data does a transforming search show?
Values,
A count of values
A list of the percentage of events the values shows up in
What operators can be used with numerical or string values?
=
!=
What operators can be used for fields ONLY with numerical values?
> =
<
<=
how would add multiple boolean to a search?
NOT (host=mail* OR host=www*)
Fill in the blanks
___ is better than ___
Inclusion is better than exclusion
What are the time operators?
S Seconds M Minutes H Hours D days W Weeks Mon Month Y Year
What are the 2 types of date ranges? give an example for each
Relative
earliest=-2h latest=-1hr
Absolute
earliest=04/20/2017:12:00:00
What is a key advantage of using indexes
Way to filter Events Early