A report named "Linux logins" populates a summary index with the search string sourcetype=linux secure | sitop src ip user. Which of the following correctly searches against the summary index for this data?
A.
index=summary sourcetype="linux_secure" | top src_ip user
B.
index=summary search name="Linux logins" | top src ip user
C.
index=summary search_name="Linux logins" | stats count by src_ip user
D.
index=summary sourcetype="linux secure" | stats count by src_ip user
the same slide deck you mention shows the answer at page 225. if you're using | sitop to create an summary you would search | top
upvoted 1 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
adamsca
3 weeks agoDerag
2 months agoDerag
2 months agoEddie_exam
2 months agoemlch
1 month, 1 week ago