How is a Search Workflow Action configured to run at the same time range as the original search?
Which function should you use with the transaction command to set the maximum total time between the earliest and latest events returned?
Consider the following search:
index=web sourcetype=access_combined
The log shows several events that share the same JSESSIONID value (SD470K92802F117). View the events as a group.
From the following list, which search groups events by JSESSIONID?
If a calculated field has the same name as an extracted field, what happens to the extracted field?
Given the macro definition below, what should be entered into the Name and Arguments fileds to correctly configured the macro?
Which option of the transaction command would be used to specify the maximum time between events in a transaction?
What does the fillnull command replace null values with, if the value argument is not specified?