Module 5: Basic Searching Flashcards

1
Q

Search and Reporting App

A

Default for searching and analyzing data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Knowledge objects, dashboards, reports created in….

A

Search and Reporting app

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Data Summary button

A

Look at data indexed by host, source, and sourcetypes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Search app: Patterns tab

A

See patterns in data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Search job vs. shared search job availability

A

10 minutes vs. 7 Days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Fast Search mode

A

Search only default fields. Field discovery disabled.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Verbose search mode

A

Returns all fields and event data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Smart search mode

A

Default. Toggles between Fast and Verbose depending on search type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Displayed timestamp defaults to

A

Local time zone of search console

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Wildcard

A

*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Boolean operators

A

And, Or, Not

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Default Boolean operator if none is specified

A

and

this that = this AND that

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Boolean operations default order

A
  1. Not
  2. Or
  3. And
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How do parenthesis affect search

A

Parenthesis evaluated first

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

\ (backslash) character in search

A

Escape

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

access_combined_wcookie source type

A

Web App

17
Q

db_audit source type

A

Database

18
Q

Bottom line of each event contains (3)

A

Host, source, sourcetype