Hmm, tough one. I'm leaning towards C, but I also kind of want to pick D just to see the look on the instructor's face when they realize the syntax is actually correct. Decisions, decisions.
Ha! D is clearly the winner here. Whoever wrote this question must be a Splunk newbie. Everyone knows you use != for field exclusions, not the NOT operator.
I think the answer is B) Every event in the network index that does not contain a StatusCode of 200 and excluding events that do not have a value in this field.
The correct answer is C. The NOT operator will include events that do not have a value in the StatusCode field, which is what the question is asking for.
Shanice
12 days agoMee
14 days agoVirgilio
17 days agoMarti
20 days agoAshleigh
3 days agoShanice
2 months agoLavera
2 months agoMalcolm
2 months agoJess
2 months agoErick
1 months agoAdela
1 months ago