Question 31

The eval command 'if' function requires the following three arguments (in order):
  • Question 32

    When should you use the transaction command instead of the scats command?
  • Question 33

    Which of the following are valid options to speed up reports? (Select all the apply.)
  • Question 34

    Which of the following statements are true for this search? (Select all that apply.) SEARCH: sourcetype=access* |fields action productld status
  • Question 35

    When using the transaction command, what does the argument maxspan do?