True or False: Fields are knowledge objects.
(A) False (B) True - answer(B) True
At search time, if an event has an equal(=) sign, the data to the left is treated as a ______ and the data to the right is treated as a ______.
(A) field name, value
(B) field name, sourcetype
(C) lookup, sourcetype
(D) lookup, value - answer(A) field name, value
The fields command allows you to do which of the following? Select all that apply.
(A) Exclude fields (fields -)
(B) Include fields (fields)
(C) Include fields (fields +) - answer(A) Exclude fields (fields -)
(B) Include fields (fields)
(C) Include fields (fields +)
In the Fields sidebar, Interesting Fields occur in at least ________ of resulting events.
(A) 20%
(B) 3%
(C) 50%
(D) 10% - answer(A) 20%
True or False: Once you rename a field, the new field name must be used in the rest of the search string.
(A) False
(B) True - answer(B) True
To remove fields from a search, you would use the _________ command.