Splunk Core Certified Advanced Power User Exam SPLK-1004 Question # 25 Topic 3 Discussion

Splunk Core Certified Advanced Power User Exam SPLK-1004 Question # 25 Topic 3 Discussion

SPLK-1004 Exam Topic 3 Question 25 Discussion:
Question #: 25
Topic #: 3

A report named "Linux logins" populates a summary index with the search string sourcetype=linux_secure | sitop src_ip user. Which of the following correctly searches against the summary index for this data?


A.

index=summary sourcetype="linux_secure" | top src_ip user


B.

index=summary search_name="Linux logins" | top src_ip user


C.

index=summary search_name="Linux logins" | stats count by src_ip user


D.

index=summary sourcetype="linux_secure" | stats count by src_ip user


Get Premium SPLK-1004 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.