Question 91

In automatic lookup definitions, the _____ fields are those that are not in the event data.
  • Question 92

    What will you learn from the results of the following search?
    sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)
  • Question 93

    Lookups allow you to overwrite your raw event.
  • Question 94

    The following searches will not return the same results. SEARCH 1: purchase SEARCH 2: action=purchase
  • Question 95

    When using | timechart by host, which field is represented in the x-axis?