Splunk index time process can be broken down into __________ phases.
How can search results be kept longer than 7 days?
What is the purpose of using a by clause with the stats command?
All users by default have WRITE permission to ALL knowledge objects.
Which search string matches only events with the status_code of 4:4?
Splunk apps are used for following (Choose three.):
What must be done in order to use a lookup table in Splunk?
NOT status = 100:
What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?
Prefix wildcards might cause performance issues.