Hmm, tough one. I'm leaning towards C, but I also kind of want to pick D just to see the look on the instructor's face when they realize the syntax is actually correct. Decisions, decisions.
Ha! D is clearly the winner here. Whoever wrote this question must be a Splunk newbie. Everyone knows you use != for field exclusions, not the NOT operator.
I think the answer is B) Every event in the network index that does not contain a StatusCode of 200 and excluding events that do not have a value in this field.
The correct answer is C. The NOT operator will include events that do not have a value in the StatusCode field, which is what the question is asking for.
Shanice
2 months agoMee
2 months agoVirgilio
2 months agoNancey
21 days agoIrma
1 months agoSharee
1 months agoLorrine
1 months agoMarti
2 months agoEvette
1 months agoTawanna
2 months agoAshleigh
2 months agoShanice
3 months agoLavera
3 months agoMalcolm
3 months agoJess
3 months agoErick
3 months agoAdela
3 months ago