Creating Field Aliases and Calculated Fields Flashcards

1
Q

What are field aliases?

A

Field aliases give you a way to normalize data over any default field (host, source, or sourcetype).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What options are you given for applying a field alias to?

A
  • Sourcetype
  • Source
  • Host
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or False: Multiple aliases can be applied to a single field.

A

True, but it is not recommended.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or False: Field Aliases are added to the fields sidebar.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

True or False: When createing a field alias, the original field is affected.

A

False.

The original field is not affected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Where do a field alias and the original field appear in the fields list?

A

Both fields appear in the All Fields and Interesting Fields lists, if they appear in at least 20% of the events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In what order are the knowledge objects Field Aliases, Field Extractions, and Lookups applied?

A

Field Extractions, Field Aliases, Lookups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

When are field aliases applied?

A

After field extractions, before lookups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Are Field Aliases case sensitive?

A

Field aliases are also case sensitive as field names are case sensitive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True or False: Field aliases can be referenced by a lookup file.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly