These users can create global knowledge objects. (Select all that apply.)
When using the transaction command, what does the argument maxspan do?
This function of the stats command allows you to return the sample standard deviation of a field.
What is the purpose of the fillnull command?
What is the purpose of a calculated field?
How do event types help a user search their data?
If a calculated field has the same name as an extracted field, what happens to the extracted field?
What will you learn from the results of the following search?
sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)