A. using findtypes could have been a way - X
B. Eventypes.conf separate file not props.conf - X
C. Possible
D. Possible
Another way is save as menu ..
Answer seems CD
BCD
Explanation:
A. By using the searchtypes command in the search bar.: This statement is false. There is no searchtypes command in Splunk for creating event types.
B. By editing the event_type stanza in the props.conf file.: This statement is true. Event types can be defined directly in the configuration files by editing the props.conf file.
C. By going to the Settings menu and clicking Event Types > New.: This statement is true. Users can create a new event type through the Splunk web interface by accessing the settings menu.
D. By selecting an event in search results and clicking Event Actions > Build Event Type.: This statement is true. Users can create a new event type directly from the search results by selecting an event and using the event actions menu.
C&D I think: There are two ways to create an event type after we have decided the search criteria. One is to run a search and then save it as an Event Type. Another is to add a new Event Type from the settings tab. We will see both the ways of creating it in this section.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
mimi01
Highly Voted 3 years, 10 months agoantukin
3 years, 9 months agoShafiqul
3 years, 8 months agoismailwale
Most Recent 3 weeks, 4 days agoNastyNutsu
1 month, 3 weeks agoStevenBzh
1 year, 3 months agoDree_Dogg
1 year, 5 months agoCactiAZ
1 year, 5 months agoMntman77
1 year, 8 months agoHarrysa
1 year, 9 months agoraizen11
1 year, 10 months agoAilen_Man
2 years, 9 months agoRayObbes
2 years, 9 months agoKEGOO
3 years, 2 months agoteems5uk
3 years, 4 months ago