Question 21
Splunk extracts fields from event data at index time and at search time.
Question 22
Lookups allow you to overwrite your raw event.
Question 23
Which statement is true about the top command?
Question 24
Log filtering/parsing can be done from _____________.
Question 25
Which command automatically returns percent and count columns when executing searches?
