I'm a bit confused on this one. I know _time is crucial, but the other options all seem reasonable as well. I'll have to review my notes on efficient search strategies before deciding.
Okay, let me think this through step-by-step. _time is definitely the most important filter to narrow down the search, so that's a given. Then it's a choice between host, index, or sourcetype as the second filter. I'm leaning towards A - _time and host, since host can help further refine the search, but I'm not 100% sure.
Hmm, I'm not sure about this one. I know _time is important for efficient searches, but I'm not sure if host or index would be the better second filter. I'll have to think this through carefully.
Tennie
2 months agoRuth
2 months agoAlberto
3 months agoJackie
3 months agoMarica
3 months agoDana
3 months agoYun
4 months agoDenise
4 months agoLamar
4 months agoJill
4 months agoTimothy
4 months agoWilda
5 months agoShizue
5 months agoWillard
7 months agoJestine
7 months agoLelia
7 months agoCarey
7 months agoReiko
6 months agoScarlet
7 months agoSol
8 months agoSarah
7 months agoDeonna
7 months agoJutta
7 months agoJustine
8 months agoSimona
7 months agoDerick
7 months agoRochell
7 months agoHortencia
8 months agoFrancene
8 months agoRodolfo
8 months agoLenny
8 months agoRonald
8 months agoVanda
8 months agoNan
7 months agoPage
7 months agoTruman
7 months agoReita
7 months agoEzekiel
8 months agoAron
8 months agoCurt
8 months agoSolange
8 months ago