Splunk uses the _______ feature to display specific values from search results in an easy-to-read spreadsheet.
Splunk uses the Statistics feature to display specific values from search results in an easy-to-read spreadsheet.
The eval command is used to _________.
The eval command is used to design new fields or modify existing fields.
Designing poor alerts can cause two types of issues: ______ and ________.
Designing poor alerts can cause two types of issues: false positives and false negatives.
_______ is a method of looking at historical data to determine how much activity is considered “normal.”
Security professionals use baselining to determine a _______.
A _______ is the condition or level that, when met, triggers an alert.
Baselining is a method of looking at historical data to determine how much activity is considered “normal.”
Security professionals use baselining to determine a threshold.
A threshold is the condition or level that, when met, triggers an alert.
________ are similar to the RPM dial found in the dashboard of a car.
**Radial gauges** are similar to the RPM dial found in the dashboard of a car.
Splunk can create location-specific reports with the ______ and ______ commands.
Splunk can create location-specific reports with the iplocation and geostats commands.
_______ are a collection of multiple visualizations in a single location.
The visualizations are placed in different sections, called ______.
**Dashboards** are a collection of multiple visualizations in a single location.
The visualizations are placed in different sections, called **panels**.
Panels can contain: (4)
Panels can contain: