Which command can include both an over and a by clause to divide results into sub-groupings?
Which of the following searches will return events containing a tag named Privileged?
The tag=Priv* search will return events containing a tag named Privileged, as well as any other tag that starts with Priv. The asterisk (*) is a wildcard character that matches zero or more characters. The other searches will not match the exact tag name.
What is the correct syntax to find events associated with a tag?
Here is an example of how you can use the tag command in a search:
index=main sourcetype=access_combined | tag status_code
You can also use the tag command with a specific tag value to find events associated with that tag. For example, the following search finds all events where the status code is tagged with success:
index=main sourcetype=access_combined | tag status_code | search tag::status_code=success
What functionality does the Splunk Common Information Model (CIM) rely on to normalize fields with different names?
