I'm a bit confused on this one. I know _time is crucial, but the other options all seem reasonable as well. I'll have to review my notes on efficient search strategies before deciding.
Okay, let me think this through step-by-step. _time is definitely the most important filter to narrow down the search, so that's a given. Then it's a choice between host, index, or sourcetype as the second filter. I'm leaning towards A - _time and host, since host can help further refine the search, but I'm not 100% sure.
Hmm, I'm not sure about this one. I know _time is important for efficient searches, but I'm not sure if host or index would be the better second filter. I'll have to think this through carefully.
Tennie
5 months agoRuth
5 months agoAlberto
6 months agoJackie
6 months agoMarica
6 months agoDana
6 months agoYun
7 months agoDenise
7 months agoLamar
7 months agoJill
7 months agoTimothy
7 months agoWilda
8 months agoShizue
8 months agoWillard
10 months agoJestine
10 months agoLelia
10 months agoCarey
10 months agoReiko
9 months agoScarlet
10 months agoSol
11 months agoSarah
10 months agoDeonna
10 months agoJutta
10 months agoJustine
11 months agoSimona
10 months agoDerick
10 months agoRochell
10 months agoHortencia
11 months agoFrancene
11 months agoRodolfo
11 months agoLenny
11 months agoRonald
11 months agoVanda
11 months agoNan
10 months agoPage
10 months agoTruman
10 months agoReita
10 months agoEzekiel
11 months agoAron
11 months agoCurt
11 months agoSolange
11 months ago