Splunk Related Exams
SPLK-1004 Exam

Which of the following would exclude all entries contained in the lookup file baditems.csv from search results?
Repeating JSON data structures within one event will be extracted as what type of fields?
Assuming a standard time zone across the environment, what syntax will always return events from between 2:00 AM and 5:00 AM?