The Field Extractor (FX) is used to extract a custom field. A report can be created using this custom field. The created report can then be shared with other people in the organization. If another person in the organization runs the shared report and no results are returned, why might this be? (select all that apply)
Which of the following knowledge objects represents the output of an eval expression?
Which of the following statements describe the Common Information Model (CIM)? (select all that apply)
Selected fields are displayed ______each event in the search results.
Which of the following statements describe calculated fields? (select all that apply)
What does the fillnull command replace null values with, it the value argument is not specified?
Which of the following statements about event types is true? (select all that apply)
Which of the following statements describe GET workflow actions?
What are the two parts of a root event dataset?
When creating a Search workflow action, which field is required?