Which function should you use with the transaction command to set the maximum total time between the earliest and latest events returned?
When multiple event types with different color values are assigned to the same event, what determines the color displayed for the events?
Which of the following searches will return events contains a tag name Privileged?
Which of the following statements describes this search?
sourcetype=access_combined I transaction JSESSIONID | timechart avg (duration)
What does the fillnull command replace null values with, it the value argument is not specified?