Using Fields Flashcards

1
Q

The fields command allows you to do which of the following? Select all that apply.

  • Include fields (fields)
  • Exclude fields (fields -)
  • Include fields (fields +)
A

Include fields (fields)
Exclude fields (fields -)
Include fields (fields +)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

At search time, if an event has an equal(=) sign, the data to the left is treated as a ______ and the data to the right is treated as a ______.

  • lookup, sourcetype
  • field name, sourcetype
  • field name, value
  • lookup, value
A

field name, value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which of the following fields are default selected fields?

  • source
  • index
  • sourcetype
  • host
A

source
sourcetype
host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or False: Fields are knowledge objects.

TRUE
FALSE

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In the Fields sidebar, Interesting Fields occur in at least ________ of resulting events.

  • 20%
  • 50%
  • 10%
  • 3%
A

20%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

To remove fields from a search, you would use the _________ command.

  • fields-
  • +fields
  • fields+
  • -fields
A

fields-

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or False: Once you rename a field, the new field name must be used in the rest of the search string.

FALSE
TRUE

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

At search time, _______ extracts fields from raw event data.

  • fields command
  • field discovery
  • field extractor
A

field discovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly