Splunk Power User 1002 Flashcards

1
Q

Search Terms are not Case Sensitive? T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Command names are not Case Sensitive? T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Clauses and Functions are not case sensitive? T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

If a command references a specific value, that value (Is / Is Not) case sensitive?

A

IS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What values from lookup tables ARE case-sensitive by default?

A

Field. Users with Admin Roles can set field values to not be case sensitive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Booleans ARE Case Sensitive. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Tag Values ARE case sensitive. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Buckets have directories containing sets of:

A

Raw Data and indexing data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Buckets have configurable what set by admin users?

A

max size & max time span

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 3 searchable buckets in Splunk?

A

Hot, Warm, and Cold

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

When are “Hot” buckets rolled into “warm” buckets?

A

when it reaches max size, max time span, or indexer is restarted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When Splunk search is run, Splunk uses what on bucket directories to determine if it needs to open the bucket, uncompress raw data, and search content inside?

A

Timestamps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Wildcards are tested after all other search terms. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Only ____ wildcards make efficient use of index

A

trailing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What happens when there is a wildcard at the beginning of a string?

A

Splunk searches all events in that time frame.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Wildcards ______ of string can cause inconsistent results

A

in the middle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Should you use wildcards to match punctuation?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the 3 search modes in Splunk?

A

Fast, Smart, and Verbose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

As events are stored by time, what is the most efficient filter?

A

Time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

After time, the default fields for _______ are most powerful.

A

index, source, host, and sourcetype.
o These fields are extracted at index time and do not need to be extracted for each search
o Use these fields to filter as early as possible in a search so processing is done on a minimum amount of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Use _____ command to extract only the fields you will need for your search

A

“fields”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

When should you apply filtering commands?

A

As early as possible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Helps determine which phase of a search is taking up the most time

A

Search Job Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Search Job Inspector dissects the behavior of searches to help understand execution costs of ____ within a search.

A

knowledge objects, search commands, & other components

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Any search job that has not expired can be inspected. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Open job inspector by:

A

running a search, clicking “Job” dropdown menu, and then “Inspect Job”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

The _______ component displays the time Splunk took when searching the index for the location of the raw data files

A

“Command Search Index”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

The ______ component displays time Splunk took to filter out events that did not match

A

“Command Search Filter”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

The ______ component is the time it took to read the events from the raw data files

A

“Command Search Raw Data”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Where do you find the “Search Job Properties” tab?

A

Under “Execution Costs”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Any search that returns ______ can be viewed as a chart

A

statistical values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Most visualizations require results structured as tables with at least __ columns

A

2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Looking at Statistics tab, if you see 2 columns, what values do the first column represent and what do the second column values represent?

A

First column = x-axis values

Second Column = y-axis values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Any stats function can be applied to the chart command. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

y-axis should always be numeric so that it can be charted. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

can remove NULL values by adding argument ______ to chart command

A

“usenull=f”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

can remove OTHER column by adding argument ______

A

“usenull=f”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What do you use to show all of the plotted series?

A

limit=0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Performs stats aggregations against time

A

Timechart Command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

_____ is always the x axis

A

Time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Timechart Command can split data with a ______ clause

A

“by”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Any stats function can be applied to timechart command. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

Only one value can be specified after the “by” modifier. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

Timechart command intelligently clusters data in time intervals dependent on ______.

A

time range selected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

To change the span of the time of the cluster, you can use the ______ argument.

A

“span”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

What command compares data over specific time periods?

A

Timewrap

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

To use timewrap command, we specify a period of time from the results of the:

A

timechart command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

In a Line Graph, you can zoom in by clicking and dragging over a time period? T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

Chart Overlay will allow you to lay a line chart of one series of data over another visualization. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

Area chart gives ability to show the data stacked. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

Can zoom into sections of the graph by clicking and dragging

A

Column chart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

Uses horizontal bars to show comparisons, and can be stacked

A

Bar Graph

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

Takes the data and visualizes the percentage for each slice and can drill down to the events for a slice by clicking on the slice

A

Pie Chart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

Shows the relationship between two discrete data values plotted on an x- and y-axis and is useful for values that do not occur at regular intervals or belong to a series

A

Scatter Chart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

Provides a visual way to view a third dimension of data.
Each chart plots against 2-dimensions on the x and y axes and the size represents the value for the 3rd dimension. 3rd field in the table command will determine the size of the bubbles in our chart.

A

Bubble Chart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

Trellis layout link allows us to split our visualizations by a selected field or aggregation. It has multiple visualizations, but originating search is only run ONCE. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

Can Transforming commands be used with visualizations?

A

yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

Top/rare – counts the frequency of fields. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

Calculates statistics between two or more fields when you do not need the data to be time-based

A

Stats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

Calculates statistics with an arbitrary field as your x-axis that is not time

A

Chart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

Calculates statistics with time as the x-axis

A

Timechart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

Plots geographic coordinates as interactive markers on a world map

A

Marker Maps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q

Uses shading to show relative metrics for predefined geographic regions

A

Choropleth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q

Lookup and add location information to events. Data such as city, country, region, latitude, and longitude can be added to events that include external IP addresses

A

iplocation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

Aggregates geographical data for use on a map visualization and uses the same functions as the stats command

A

Geostats Command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

The Geostats command only accepts ___ “by” argument or arguments

A

1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

To control column count, what argument can be used?

A

“globallimit”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
68
Q

Geostats can be used with iplocation. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
69
Q

View data as a geographical location, uses shading to show relative metrics over predefined locations of a map

A

Choropleth Maps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
70
Q

To use choropleth you will need a ______ file that defines region boundaries

A

KMZ (Keyhold Markup Language) (.kml)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
71
Q

Used to prepare our events for use in a choropleth and

adds a field that includes geographical data structures that match polygons on our map

A

Geom Command

geom featureIdField=, or
sourcetype=crime_data cc=USA | lookup geo_us_states latitude, longitude | stats count by featureId | geom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
72
Q

2 different types of visualizations you can use to display

A

Single Value, Gauges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
73
Q

What computes moving averages of field values?

A

Trendline command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
74
Q

What 3 arguments are required in a Trendline command?

A

trendtype, time period, field

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
75
Q

What options does the Field Format give you?

A

o Wrap results
o Show row numbers
o Change click selection from cell to row
o Add a data overlay – can be a heat map of values or highlight the high and low values in the table

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
76
Q

Computes the sum of all numeric fields for each event/row and create a total column

A

Addtotals Command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
77
Q

Used to calculate and manipulate field values

A

Eval Command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
78
Q

Arithmetic, concatenation, and Booleans are supported by the Eval command. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
79
Q

In the Eval Command, newly created field values are case-sensitive. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
80
Q

Converts numerical values to strings so that they can be joined with other strings

A

Tostring Function. After using tostring, fields may not sort numerically because the field values are now ASCII values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
81
Q

Can be used if you want to format values without changing characteristics of underlying values

A

Fieldformat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
82
Q

Allows you to evaluate arguments and create values depending on the results

A

Eval command IF Function.
• takes 3 arguments [ “if(x, y, z)” ]
o x – a Boolean expression
o y – used if Boolean expression evaluates to true
o z – used if Boolean expression evaluates to false
o y & z must be in double quotes if not numerical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
83
Q

Can be used to filter results at any time in the search and allows you to use search terms further down the pipeline

A

Search Command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
84
Q

A Search command cannot compare values from 2 different fields. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
85
Q

Filters events to only keep the results that evaluate as true

A

Where Command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
86
Q

Asterisks cannot be used as a wildcard inside eval or where commands. T or F

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
87
Q

What replaces any null values in your events

A

Fillnull Command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
88
Q

Maximum total time between earliest and latest

A

maxspan

89
Q

maximum total time between events

A

maxpause

90
Q

Use Transactions when

A

o You need to see events correlated together

o When events need to be grouped on start and end values

91
Q

Use stats when

A

o You want to see results of a calculation

o When events need to be grouped on a field value

92
Q

Transaction has a limit of how many events?

A

1000

93
Q

What is the limit for Stats?

A

no limit

94
Q

If given a choice between stats and transactions, which should you use?

A

stats

95
Q

What are tools that help you and your users discover and analyze your data?

A

Knowledge Objects

96
Q

Knowledge objects are used for:

A
o	Data interpretation
o	Classification
o	Enrichment
o	Normalization
o	Search time mapping
97
Q

Properties of knowledge objects are that it:

A

o Can be created by one user and shared with other users based on permission settings
o Can be saved and reused by multiple people or in multiple apps
o Can be used in a search

98
Q

Name 5 types of knowledge objects:

A
  1. data interpretation
  2. data classification
  3. data enrichment
  4. normalization
  5. datasets
99
Q

What is the order for common naming convention of objects?

A

group, type, platform, category, time, and description

100
Q

What are three predefined ways that knowledge objects can be displayed to users?

A

Private
Specific apps
all apps

101
Q

What does CIM stand for?

A

Common Information Model

102
Q

The _____ allows you to use a graphical user interface to extract fields that persist as knowledge objects making them reusable in searches

A

Field Extractor

103
Q

2 different methods the field extractor can use to extract data

A

o Regular expressions – work well when you have unstructured data and events that you want to extract fields from
o Delimiters – used when your events contain fields separated by a character

104
Q

_____ will display events that do not contain extracted fields

A

Non-matches

105
Q

After manually editing a regular expression, you cannot go back to the Field Extractor UI. T or F

A

True

106
Q

Delimiter can be a:

A

space, comma, tab, other

107
Q

To be able to select a value from an already extracted field, you must open the “Existing Fields” menu, and turn off the highlight for the field that includes the value. T or F

A

True

108
Q

_____ give you a way to normalize data over any default field.

A

Field Aliases

109
Q

_____ are applied after field extractions, before lookups.

A

Field Aliases

110
Q

How do you create a field alias?

A

“Settings” -> “Fields” -> “Field aliases”

111
Q

Can apply aliases based on?

A

Sourcetype, source, host

112
Q

Old fields are still available to search? T or F

A

True

113
Q

Once a field alias is defined, they can be referenced in?

A

A lookup table

114
Q

What are calculated fields used for?

A

repetitive, long, and complex eval commands

115
Q

Calculated fields must be based on an extracted field? T or F

A

True

116
Q

Select destination app and then which sourcetype, source, or host to apply the _____ to.

A

calculated field

117
Q

Calculated fields must or must not be based on extracted or discovered fields?

A

MUST

118
Q

Allows you to designate descriptive names for key-value pairs and enables you to search for events that contain particular field values

A

Tags

119
Q

Are Tag values(names) case sensitive?

A

Yes

120
Q

What are 3 ways to search for tags?

A

tag=privileged
tag::user=privileged
tag=p*

121
Q

Allows you to categorize events based on search terms

A

Event Type

122
Q

What do event types help with?

A

simplify searches

give quick visual feedback

123
Q

Do event types show up in fields list?

A

yes

124
Q

What does a word in Blue in a Splunk search mean?

A

command

125
Q

What does a word in green in a Splunk search mean?

A

command argument

126
Q

What does a word in pink in a Splunk search mean?

A

function

127
Q

What does a word in orange in a Splunk search mean?

A

boolean or keyword modifier

128
Q

What does a word in gray in a Splunk search mean?

A

inline comment (e.g. ```Plot the count of results over the past 24 hours.``)

129
Q

In which is a time range not included? Event Type or Saved Reports

A

Event Type

130
Q

Can you share saved reports with other Splunk users?

A

Yes

131
Q

_____ are search strings, or portions of search strings, that can be reused in multiple places within Splunk

A

Macros

132
Q

When are Macros useful

A

frequent searches with complicated search syntax

133
Q

What are 3 features that distinguish macros from other knowledge objects?

A

Store entire search strings
They are time range independent
Can pass arguments to the search

134
Q

How do you create a macro?

A

“Settings” > “Advanced Search” > “Search macros”

135
Q

What is the syntax for a macro? (Flip card for reference)

A

o Ex: “… | convertUSD

o Need to use backtick character (`)

136
Q

How do you change the definition of a macro to accept an argument?

A

by adding the name of the argument surrounded by dollar signs ($)
o Required to name the macro with how many arguments it requires [ex: “us_sales(2)” ]
o Ex: “… eval $moolah$ = … “

137
Q

What key combination allows you to preview your search without running it?

A

CTRL + SHIFT + E

138
Q

What is a collection of hierarchically structured datasets?

A

Data Model

139
Q

A data model consists of 3 types of datasets. What are they?

A

Events, Searches, & Transactions

140
Q

Any field can be made available to the data model. T or F

A

True

141
Q

Data models provide the datasets for what?

A

Pivots

142
Q

_____ data models cannot be edited.

A

Accelerated

143
Q

_____ data models cannot be accelerated.

A

Private

144
Q

How do you add fields?

A

“Add field” Dropdown

145
Q

What are the fields Splunk extracts from our data? These can be default fields or manually extracted fields.

A

Auto-Extracted Fields

146
Q

What does selecting the type of data allow us to do?

A

allows us to decide how the data should be recognized (String, number, Boolean, IP data)

147
Q

What does selecting a flag allow us to do?

A

allows us to choose what attributes are shown or required

148
Q

What are the four settings for Flags?

A

Optional
Required
Hidden
Hidden & Required

149
Q

What represents transactions using fields that have already been added to the data model?

A

Root Transactions

150
Q

Root Transactions do not benefit from data model _____.

A

acceleration

151
Q

What is the recommended way to use Pivot? UI or Pivot Command

A

UI

152
Q

What does CIM stand for?

A

Common Information Model

153
Q

What maps all data to a defined method and normalizes to common language for field values?

A

CIM

154
Q

Data can be normalized at _____ time or at _____ time using knowledge objects.

A

Index, search

155
Q
\_\_\_\_\_ should be used for:
o	Field extractions
o	Aliases
o	Event types
o	Tags
A

CIM schema

156
Q

_____ _____ can be shared globally across all apps.

A

Knowledge objects

157
Q

_____ is a methodology for normalizing data and can correlate data from different sources.

A

CIM

158
Q

CIM is an app that can coexist with other apps on a _____ Splunk deployment

A

Single

159
Q

By default, CIM datasets search across all _____

A

indexes

160
Q

Where would you download the CIM app?

A

Splunkbase

161
Q

What are the included data models in the CIM addon?

A

Alerts, Email, Database

162
Q

CIM data models are/are not accelerated by default?

A

are not

163
Q

Data model name and dataset name ARE/ARE NOT case-sensitive

A

Are

164
Q

Fields used in Data Models do not have to be extracted before creating the datasets. T or F

A

T

165
Q

It is suggested that you name your knowledge objects using _____ segmented keys.

A

6

166
Q

_____ are knowledge objects that can be scheduled and run a script.

A

Reports

167
Q

What is the only writeable bucket type?

A

The hot bucket

168
Q

By what filter are indexes divided into buckets?

A

By time

169
Q

What are the 4 types of searches in Splunk (by performance)

A

Dense, Sparse, Super Sparse, Rare

170
Q

In searches, what is the scanCount?

A

The number of events scanned for that particular search

171
Q

What are the requirement of the underlying search in order to get multi-series table?

A

The underlying search must use reporting search commands like chart or timechart

172
Q

What are the seven chart types?

A

Line, Area, Column, Bar, Bubble, Scatter and Pie

173
Q

What is a trait of scatter charts?

A

Can only show two dimensions. Shows trends in the relationship between discrete data values

174
Q

What is a trait of bubble charts?

A

Provides a visual way to view a three dimensional series

175
Q

What are two commonly used clauses for chart?

A

over and by

176
Q

(True/False) Null values are not shown by default by chart and timechart

A

false

177
Q

What is a workflow action

A

Execute workflow actions from an event in your search results to interact with external resources or run another search

178
Q

What does the over and by clauses do when used with chart?

A

divides the data into sub-groupings

179
Q

(True/False) You can only split chart results over two dimensions

A

True

180
Q

Chart and timechart commands automatically filter results to include how many values?

A

10

181
Q

What happens to surplus resulting values of chart and timechart commands?

A

They are grouped into other

182
Q

What is always the value on the x-axis for timechart?

A

_time

183
Q

(True/False) Functions and arguments used with stats and chart can not be used with timechart

A

False

184
Q

(True/False) As with chart, it is possible to split timechart by two fields

A

False. It is only possible to split by one field

185
Q

What is the argument for adjusting sampling interval of timechart?

A

span

186
Q

What does the trendline command do?

A

allows you to overlay a computed moving average on a chart

187
Q

What is the syntax of the trendline command?

A

trendline (field) [AS newfield]

188
Q

What command can be used to look up and add location information to an event?

A

iplocation

189
Q

What information does the iplocation command include?

A

city, country, region, latitude and longitude

190
Q

What is the data-requirement for the geostats command?

A

Data must include latitude and longitude values

191
Q

These arguments are used to control column counts when using the geostats command

A

globallimit and locallimit

192
Q

This command is used to compute statistical functions and render a cluster map

A

geostats

193
Q

What command can be used to show relative metrics for predefined geographic regions?

A

geom

194
Q

(True/False) A sparkline is an inline chart, that can be added to timechart

A

True

195
Q

(True/False) Automatically totaling of every columns can be done by using the Format option

A

True

196
Q

This command can be used to add total of all or selected fields

A

addtotals

197
Q

The row option for addtotals does what?(if enabled)

A

creates a column that contains numeric totals for each row

198
Q

The column option for addtotals does what?(if enabled)

A

creates a row that contains numeric totals for each column

199
Q

What does the labelfield option for addtotals specify?

A

What field the label should be placed in (in general, this should be the leftmost and first field)

200
Q

The eval command can be used to

A

perform calculations, convert, round and format values, use conditional statements

201
Q

This command allows you to calculate and manipulate field values in your report

A

eval

202
Q

(True/false) Results of eval can be written to existing field

A

True

203
Q

What happens with a destination field value if the field is the same as the resulting field of the eval command?

A

The field value gets overwritten by the resulting value outputted from the eval command

204
Q

(True/False) Indexed data get modified after field values are overwritten by the eval command.

A

false

205
Q

This operator is used for concatenation

A

+

206
Q

This function can be used to set the value of a field to the number of decimals you specify

A

round

207
Q

(True/False) The tostring function can be used with eval

A

True

208
Q

How can you use eval to format numeric field values to strings?

A

By adding characters to the field values

209
Q

What separator is used when having multiple expressions used with eval command?

A

comma

210
Q

If function used with eval: What is field value of SalesTerritory for a VendorID of 80000 in the following evaluation?:
| eval SalesTerritory = if((VendorID >= 7000 AND VendorID <8000), “Asia”, “Rest of the World”)

A

Rest of the World

211
Q

(True/False) The search command treats field values in a case-insensitive manner

A

True

212
Q

(True/False) The where command treats field values in a case-insensitive manner

A

False

213
Q

(True/False) Unqouted or single-quoted strings are treated as fields.

A

True

214
Q

To be able to do wildcard searches with the where command, this operator must be used

A

like

215
Q

What is the fillnull value used for?

A

To replace null values in fields. Default replacement value is 0.

216
Q

What is a transaction?

A

A transaction is any group of related events that span time

217
Q

What is the syntax of the transaction command?

A

transaction field-list. field-list argument is a list of one or multiple fields.

218
Q

(True/False) Transaction command creates a single event from a group of events

A

True

219
Q

This field is produced by running the transaction command

A

duration - difference between timestamp of first and last event in the transaction