This search will return 20 results. SEARCH: error | top host limit = 20
What is the correct order of steps for creating a new lookup?
1. Configure the lookup to run automatically
2. Create the lookup table
3. Define the lookup
When refining search results, what is the difference in the time picker between real-time and relative time ranges?
Which search would return events from the access_combined sourcetype?
Splunk automatically determines the source type for major data types.
What is the proper SPL terminology for specifying a particular index in a search?
Which command automatically returns percent and count columns when executing searches?
Which of the following are Splunk premium enhanced solutions? (Choose three.)
Which of the following is the recommended way to create multiple dashboards displaying data from the same search?
Which of the following is the appropriately formatted SPL search?