SPLK-1002 · Question #29
To identify all of the contributing events within a transaction that contains at least one REJECT event, which syntax is correct?
The correct answer is B. Index-main | transaction sessionid | search REJECT. Option B (index=main | transaction sessionid | search REJECT) is the correct two-step approach: first, transaction sessionid groups all related events sharing the same sessionid into complete transactions; then search REJECT filters to return only those entire transactions that…
Question
To identify all of the contributing events within a transaction that contains at least one REJECT event, which syntax is correct?
Options
- AIndex-main | REJECT trans sessionid
- BIndex-main | transaction sessionid | search REJECT
- CIndex=main | transaction sessionid | whose transaction=reject
- DIndex=main | transaction sessionid | where transaction=reject''
How the community answered
(38 responses)- A3% (1)
- B84% (32)
- C3% (1)
- D11% (4)
Explanation
Option B (index=main | transaction sessionid | search REJECT) is the correct two-step approach: first, transaction sessionid groups all related events sharing the same sessionid into complete transactions; then search REJECT filters to return only those entire transactions that contain the word REJECT - preserving all contributing events within matching transactions, not just the REJECT event itself. (A) has invalid SPL syntax with 'REJECT trans'. (C) uses a non-existent 'whose' keyword. (D) uses where transaction=reject which is not valid syntax for this use case - where is used for field comparisons, not for searching within transaction text.
Topics
Community Discussion
No community discussion yet for this question.