What will you learn from the results of the following search?
sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)
Which of the following can be used with the eval command tostring function (select all that apply)
When using timechart, how many fields can be listed after a by clause?
What are the two parts of a root event dataset?