Consider the following search:
Index=web sourcetype=access_combined
The log shows several events that share the same JSESSIONID value (SD404K289O2F151). View the events as a group. From the following list, which search groups events by JSESSIONID?
The following searches will return the same results. SEARCH 1: ssh error SEARCH 2: ssh AND error
Calculated fields can be based on which of the following?
When using the Field Extractor (FX), which of the following delimiters will work? (Choose all that apply.)