Select this in the fields sidebar to automatically pipe you search results to the rare command

Select this in the fields sidebar to automatically pipe you search results to the rare command
A . events with this field
B . rare values
C . top values by time
D . top values

Answer: B

Explanation:

The fields sidebar is a panel that shows the fields that are present in your search results2. The fields sidebar has two sections: selected fields and interesting fields2. Selected fields are fields that you choose to display in your search results by clicking on them in the fields sidebar or by using the fields command2. Interesting fields are fields that appear in at least 20 percent of events or have high variability among values2. For each field in the fields sidebar, you can select one of the following options: events with this field, rare values, top values by time or top values2. If you select rare values, Splunk will automatically pipe your search results to the rare command, which shows the least common values of a field2. Therefore, option B is correct, while options A, C and D are incorrect because they do not pipe your search results to the rare command.

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments