What is the purpose of using a by clause with the stats command?
In the Fields sidebar, what does the number directly to the right of the field name indicate?
By default, how long does Splunk retain a search job?
When using the top command in the following search, which of the following will be true about the results?index='main' sourcetype='access_*' action='purchase' | top 3 statusCode by user showperc=f countfield=status_code_count
When is an alert triggered?