Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Splunk Core Certified Power User Exam SPLK-1002 Question # 49 Topic 5 Discussion

Splunk Core Certified Power User Exam SPLK-1002 Question # 49 Topic 5 Discussion

SPLK-1002 Exam Topic 5 Question 49 Discussion:
Question #: 49
Topic #: 5

Consider the following search:

index=web sourcetype=access_corabined

The log shows several events that share the same jsesszonid value (SD462K101O2F267). View the events as a group.

From the following list, which search groups events by jSSESSIONID?


A.

index=web sourcetype=access_combined I transaction JSESSZONID I search SD462K101C2F267


B.

index=web sourcetype=access_combined SD462K101O2F267 | table JSESSIONID


C.

index=web sourcetype=access_combined | highlight JSESSIONID | search SD462K101O2F267


D.

index=web sourcetype=access_combined JSESSTONID < SD4€2K101O2F267 >


Get Premium SPLK-1002 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.