Hmm, tough one. I'm leaning towards C, but I also kind of want to pick D just to see the look on the instructor's face when they realize the syntax is actually correct. Decisions, decisions.
Ha! D is clearly the winner here. Whoever wrote this question must be a Splunk newbie. Everyone knows you use != for field exclusions, not the NOT operator.
I think the answer is B) Every event in the network index that does not contain a StatusCode of 200 and excluding events that do not have a value in this field.
The correct answer is C. The NOT operator will include events that do not have a value in the StatusCode field, which is what the question is asking for.
Shanice
27 days agoMee
29 days agoVirgilio
1 months agoIrma
5 days agoSharee
9 days agoLorrine
12 days agoMarti
1 months agoEvette
13 days agoTawanna
14 days agoAshleigh
18 days agoShanice
2 months agoLavera
2 months agoMalcolm
2 months agoJess
2 months agoErick
2 months agoAdela
2 months ago