Which of these is NOT a field that is automatically created with the transaction command?
Which statement is true?
When can a pipe follow a macro?
The eval command allows you to do which of the following? (Choose all that apply.)
Given the following eval statement:
...| eval fieldl - if(isnotnull(fieldl),fieldl,0), field2 = if(isnull
Which of the following is the equivalent using f ilinull?
Which of the following searches show a valid use of macro? (Select all that apply)
The gauge command:
What is required for a macro to accept three arguments?
What does the fillnull command replace null values with, if the value argument is not specified?
These allow you to categorize events based on search terms.
Select your answer.