What is the correct order of steps for creating a new lookup?
1. Configure the lookup to run automatically
2. Create the lookup table
3. Define the lookup
Which component of Splunk is primarily responsible for saving data?
Fields are searchable key value pairs in your event data.
It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.
By default, how long does Splunk retain a search job?
What happens when a field is added to the Selected Fields list in the fields sidebar'?
Lookups allow you to overwrite your raw event.
The better way of writing search query for index is:
What is the default lifetime of every Splunk search job?
Which command is used to review the contents of a specified static lookup file?