Pivots and Datasets Flashcards

1
Q

What is the purpose of a pivot?

A

Design reports in simple to use interface without ever having to craft a search string

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a data model?

A

A knowledge object that provides the data structure that drives pivots

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What job roles have access to create data models?

A

ADMIN, POWER (as they have knowledge of the search language)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a dataset?

A

A smaller set of the data defined for a specific purpose, represented as tables with field names for columns and field values for cells

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How would u explain a dataset easily

A

Like slices of data
i.e. top slice shows all events
selecting successful child events will filter to events not ending in error
Think of the child datasets as an ‘AND’ boolean i.e. sourcetype=access_combined AND status=200

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the only type of serach you can use for a Pivot, provide and example

A

NON TRANSFORMING search

i.e sourceype=access_combined status=404

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

how do you create an instant pivot?

A

Click on the ‘Instant Pivot’ button on the visualisation tab

How well did you know this?
1
Not at all
2
3
4
5
Perfectly