Which of the following is the best way to create a report that shows the last 24 hours of events?

Posted by: Pdfprep Category: SPLK-1001 Tags: , ,

Which of the following is the best way to create a report that shows the last 24 hours of events?
A . Use earliest=-1d@d latest=@d
B . Set a real-time search over a 24-hour window
C . Use the time range picket to select “Yesterday”
D . Use the time range picker to select “Last 24 hours”

Answer: D

Explanation:

Reference: https://answers.splunk.com/answers/153100/how-to-get-the-event-count-for-the-last-24-hours­as-a-scheduled-report.html

Leave a Reply

Your email address will not be published.