What information must be included when using the datamodel command?
Which of the following knowledge objects can reference field aliases?
These kinds of charts represent a series in a single bar with multiple sections
Which of the following statements describe the search below? (select all that apply)
Index=main I transaction clientip host maxspan=30s maxpause=5s
Which workflow action method can be used the action type is set to link?
Which of the following is one of the pre-configured data models included in the Splunk Common Information Model (CIM) add-on?
A Splunk app is configured to extract domain names in web service logs and specify them as a field named domain.
What workflow action would return an external IP lookup for the field named domain?
What approach is recommended when using the Splunk Common Information Model (CIM) add-on to normalize data?
What does the fillnull command do in this search?
index=main sourcetype=http:log | fillnull value="Unknown" src
Where are the results of eval commands stored?