nerdexam
Splunk

SPLK-1001 · Question #170

SPLK-1001 Question #170: Real Exam Question with Answer & Explanation

The correct answer is C. sourcetype=firewall | rare count=15 dest_ip. See the full explanation below for the reasoning.

Question

Which search will return the 15 least common field values for the dest_ip field?

Options

  • Asourcetype=firewall | rare num=15 dest_ip
  • Bsourcetype=firewall | rare last=15 dest_ip
  • Csourcetype=firewall | rare count=15 dest_ip
  • Dsourcetype=firewall | rare limit=15 dest_ip

Community Discussion

No community discussion yet for this question.

Full SPLK-1001 Practice