問題文
A report built with the top command over a field with 200 distinct values shows counts that sum to far less than the total number of matched events. What explains the gap?
選択肢
- The percentages are computed against the returned rows rather than the matched events, which makes the counts appear smaller than they are.
- The rows beyond the limit are simply not returned, and by default the command does not add a row summarizing them.
- The command adds a row for the remaining values by default, so the analyst is looking at a filtered view.
- Each event is counted once per value, so events holding several values are undercounted.