By default, how long does Splunk retain a search job?
What must be done before an automatic lookup can be created? (Choose all that apply.)
Which of the following Splunk components typically resides on the machines where data originates?
What determines the scope of data that appears in a scheduled report?
When writing searches in Splunk, which of the following is true about Booleans?
Which search string only returns events from hostWWW3?