A. using findtypes could have been a way - X
B. Eventypes.conf separate file not props.conf - X
C. Possible
D. Possible
Another way is save as menu ..
Answer seems CD
BCD
Explanation:
A. By using the searchtypes command in the search bar.: This statement is false. There is no searchtypes command in Splunk for creating event types.
B. By editing the event_type stanza in the props.conf file.: This statement is true. Event types can be defined directly in the configuration files by editing the props.conf file.
C. By going to the Settings menu and clicking Event Types > New.: This statement is true. Users can create a new event type through the Splunk web interface by accessing the settings menu.
D. By selecting an event in search results and clicking Event Actions > Build Event Type.: This statement is true. Users can create a new event type directly from the search results by selecting an event and using the event actions menu.
C&D I think: There are two ways to create an event type after we have decided the search criteria. One is to run a search and then save it as an Event Type. Another is to add a new Event Type from the settings tab. We will see both the ways of creating it in this section.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
mimi01
Highly Voted 4 years, 3 months agoantukin
4 years, 3 months agoShafiqul
4 years, 1 month agoismailwale
Most Recent 6 months, 1 week agoNastyNutsu
7 months, 1 week agoStevenBzh
1 year, 8 months agoDree_Dogg
1 year, 10 months agoCactiAZ
1 year, 11 months agoMntman77
2 years, 2 months agoHarrysa
2 years, 3 months agoraizen11
2 years, 3 months agoAilen_Man
3 years, 2 months agoRayObbes
3 years, 2 months agoKEGOO
3 years, 8 months agoteems5uk
3 years, 9 months ago