.
Lookup
Csvlookup
Inputlookup
Outputlookup
Preset - Relative: 30-seconds ago
Relative - Earliest: 30-seconds ago, Latest: Now
Real-time - Earliest: 30-seconds ago, Latest: Now
Advanced - Earliest: 30-seconds ago, Latest: Now
Any newly created dashboard will include that report.
B. There are no benefits to creating dashboard panels from reports.
C. It makes the dashboard more efficient because it only has to run one search string.
D. Any change to the underlying report will affect every dashboard that utilizes that report.
Both field names and field values ARE case sensitive.
Field names ARE case sensitive; field values are NOT.
Field values ARE case sensitive; field names ARE NOT.
Both field names and field values ARE NOT case sensitive.
Returns the least common field values of a given field in the results.
Returns the most common field values of a given field in the results.
Returns the top 10 field values of a given field in the results.
Returns the lowest 10 field values of a given field in the results.
Or
Not
And
Xor
Lists all values of a given field.
Lists unique values of a given field.
Returns a count of unique values for a given field.
Returns the number of events that match the search.
Click All Fields and select the field to add it to Selected Fields.
Click Interesting Fields and select the field to add it to Selected Fields.
Click Selected Fields and select the field to add it to Interesting Fields. This scenario isn't possible because all fields returned from a search always appear in the fields sidebar.
This scenario isn't possible because all fields returned from a search always appear in the fields sidebar.
#
%
A
A#
Time
Fast mode
Sourcetype
Selected fields
Count stats vendor_action
Count stats (vendor_action)
Stats count (vendor_action)
Stats vendor_action (count)
Host
Index
Source
Sourcetype
You can modify the search string in the panel, and you can change and configure the visualization.
You can modify the search string in the panel, but you cannot change and configure the visualization.
You cannot modify the search string in the panel, but you can change and configure the visualization.
You cannot modify the search string in the panel, and you cannot change and configure the visualization.
You can modify the search string in the panel, and you can change and configure the visualization.
You can modify the search string in the panel, but you cannot change and configure the visualization.
You cannot modify the search string in the panel, but you can change and configure the visualization.
You cannot modify the search string in the panel, and you cannot change and configure the visualization.
Include all formatting commands before any search terms
Include at least one function as this is a search requirement
Include the search terms at the beginning of the search string
Avoid using formatting clauses as they add too much overhead
Any search can be saved as a report
Only searches that generate visualizations
Only searches containing a transforming command
Only searches that generate statistics or visualizations
Dashboards
Metadata only
Non-interesting fields
Field descriptions
Action+purchase
Action=purchase
Action | purchase
Action equal purchase
A field that appears in any event
A field that appears in every event
A field that appears in the top 10 events
A field that appears in at least 20% of the events
Parentheses
@ or # symbols
Quotation marks
Relational operators such as =, <, or >
CSV, JSON, PDF
CSV, XML JSON
Raw Events, XML, JSON
Raw Events, CSV, XML, JSON
Count, sum, add
Count, sum, less
Sum, avg, values
Sum, values, table
No events will be returned.
Splunk will prompt you to specify an index.
All non-indexed events to which the user has access will be returned.
Events from every index searched by default to which the user has access will be returned.
Index=security Error Fail
Index=security error OR fail
Index=security "error failure"
Index=security NOT error NOT fail
Saving the item to a report
Adding the item to the search.
Adding the item to a dashboard
Saving the search to a JSON file.