Which of the following knowledge objects represents the output of an eval expression?
A. Field extractions
B. Eval fields
C. Calculated fields
D. Calculated lookups
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
When using | timchart by host, which filed is representted in the x-axis?
A. time
B. date
C. -time
D. host
正解:B
質問 3:
To create a tag, which of the following conditions must be met by the user?
A. Have the Power role at a minimum.
B. Be able to edit the sourcetype the tag applies to.
C. Identify at least one field:value pair.
D. Must have the tag capability associated with their user role.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
For the following search, which command would further filter for only IP addresses present more than five times?
A. index=games | where IP > 5
B. index=games I search IP > 5
C. index=games | search IP_Count > 5
D. index=games I stats count as IP_count by IP B. | where IP_count > 5
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Which of the following statements describes the use of the Field Extractor (FX)?
A. Fields extracted using the Field Extractor do not persist and must be defined for each search.
B. The Field Extractor automatically extracts all fields at search time.
C. The Field Extractor uses PERL to extract fields from the raw events.
D. Fields extracted using the Field Extractor persist as knowledge objects.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
What is the purpose of the fillnull command?
A. Create a new field based on the values in an existing field.
B. Rename a specific field in the search results.
C. Replace empty values with a specified value.
D. Replace all values in a specific field with a default value.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
堀*弓 -
試験に受かりました。覚えてきた問題が試験にも同じのが出てて良かったです。合格しました。とても感謝しています