For the following search, which field populates the x-axis?index=security sourcetype=linux_secure | timechart count by action
Which knowledge object is used to normalize field names to comply with the Splunk Common Information Model (CIM)?
Which of the following transforming commands can be used with transactions?
What is the correct format for naming a macro with multiple arguments?
What are search macros?
How is a macro referenced in a search?