Question 91
In automatic lookup definitions, the _____ fields are those that are not in the event data.
Question 92
What will you learn from the results of the following search?
sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)
sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)
Question 93
Lookups allow you to overwrite your raw event.
Question 94
The following searches will not return the same results. SEARCH 1: purchase SEARCH 2: action=purchase
Question 95
When using | timechart by host, which field is represented in the x-axis?