Splunk Core Certified Power User Exam SPLK-1002 Question # 17 Topic 2 Discussion

Splunk Core Certified Power User Exam SPLK-1002 Question # 17 Topic 2 Discussion

SPLK-1002 Exam Topic 2 Question 17 Discussion:
Question #: 17
Topic #: 2

To identify all of the contributing events within a transaction that contains at least one REJECT event, which syntax is correct?


A.

Index-main | REJECT trans sessionid


B.

Index-main | transaction sessionid | search REJECT


C.

Index=main | transaction sessionid | whose transaction=reject


D.

Index=main | transaction sessionid | where transaction=reject’’


Get Premium SPLK-1002 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.