When using the top command in the following search, which of the following will be true about the results?
index="main" sourcetype="access_*" action="purchase" | top 3 statusCode by user showperc=f countfield=status_code_count
When looking at a statistics table, what is one way to drill down to see the underlying events?
After running a search, what effect does clicking and dragging across the timeline have?
How does Splunk determine which fields to extract from data?
Which command is used to validate a lookup file?