Splunk
SPLK-5001 · Question #119
SPLK-5001 Question #119: Real Exam Question with Answer & Explanation
Sign in or unlock SPLK-5001 to reveal the answer and full explanation for question #119. The question stem and answer options stay visible for context.
Question
Which of the following SPL searches is likely to return results the fastest?
Options
- Asrc_port=2938 AND protocol=tcp | stats count by src_ip | search
- Bindex=network src_port=2938 protocol=tcp | stats count by src_ip |
- Cindex=network sourcetype=netflow src_ip=1.2.3.4 src_port=2938
- Dsrc_ip=1.2.3.4 src_port=2938 protocol=tcp | stats count
Unlock SPLK-5001 to see the answer
You've previewed enough free SPLK-5001 questions. Unlock SPLK-5001 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.