MultipleChoice
There is a global search named ''global_search'' defined on a form as shown below:
index-_internal source-*splunkd.log | stats count by component, log_level
Which of the following would be a valid post-processing search? (Select all that apply.)
OptionsMultipleChoice
Searching ''index=_internal metrics | head 3'' from Splunk Web returned the following events:
04-12-2018 18:39:43.514 +0200 INFO Metrics -- group=thruput, name=thruput, instantaneous_kbps=0.9651774014563425, instantaneous_eps=5.645638802094809, average_kbps=1.198995639527069, total_k_processed=2676, kb=29.91796875, ev=175, load_average=3.85888671875
04-12-2018 18:39:43.514 +0200 INFO Metrics -- group_thruput, name_syslog_output, instantaneous_kbps=0, instantaneous_eps_0, average_kbps=0, total_k_processed=0, kb=0, ev=0
04-12-2018 18:39:43.513 +0200 INFO Metrics -- group_thruput, name_index_thruput, instantaneous_kbps=0.9651773703189551, instantaneous_eps=4.87137960922438, average_kbps=1.1985932324065556, total_k_processed=2675, kb=29.91796875, ev=151
When the same search is required from a REST API call, which fields will be given? (Select all that apply.)
OptionsMultipleChoice
Which HTTP Event Collector (HEC) endpoint should be used to collect data in the following format?
{''message'':''Hello World'', ''foo'':''bar'', ''pony'':''buttercup''}
Options