Which of the following would exclude all entries contained in the lookup file baditems.csv from search results?
Repeating JSON data structures within one event will be extracted as what type of fields?
A report named "Linux logins" populates a summary index with the search string sourcetype=linux_secure | sitop src_ip user. Which of the following correctly searches against the summary index for this data?
When running a search, which Splunk component retrieves the individual results?