Which of the following is the appropriately formatted SPL search?
Which of the following is the appropriately formatted SPL search?
The appropriately formatted SPL search is 'index=security sourcetype=linux_secure (invalid OR failed) | stats count as "Potential Issues"'. This query correctly uses the 'stats' command with 'count' to aggregate the events that meet the criteria and labels this count as 'Potential Issues'.
B pdf page 55
Is it not A