Which search would return events from the access_combined sourcetype?
Which search would return events from the access_combined sourcetype?
To return events from the access_combined sourcetype, you need to use the correct field name and value. In this case, the field name 'sourcetype' is case sensitive and should be lowercase, and the value 'access_combined' should be exactly as specified. Therefore, the correct search query should be 'sourcetype=access_combined'.
C is correct answer ,field name is case sensitive not values
C is correct
C is correct. Field names are case sensitive.
field names are sensitive not values
C correct. field name (sourcetype) -> case sensitive field value (Acces_Combined) -> NOT case sensitive
Field name is case sensitive and field value is not
If all the answers were right on this exam, I imagine that these exam questions would not be available for long.
C is correct
field value is not case sensitive.
Field name is case sensitive so the correct answer is C
C is correct.
C is correct
C is correct
C because field names are case sensitive field values are not
C is correct
C is correct.
C is correct