- (Exam Topic 1)
Which of the following are required to create a POST workflow action?
Correct Answer:
B
- (Exam Topic 2)
What will you learn from the results of the following search? sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)
Correct Answer:
A
- (Exam Topic 1)
Which delimiters can the Field Extractor (FX) detect? (select all that apply)
Correct Answer:
ABCD
- (Exam Topic 1)
In which of the following scenarios is an event type more effective than a saved search?
Correct Answer:
D
- (Exam Topic 2)
Using the export function, you can export search results as _______.( Select all that apply)
Correct Answer:
AB