フリー問題

Splunk Certified Cybersecurity Defense Engineer のフリー問題 2 / 20 問目

問題文

An application writes multi-line stack traces, and each record begins with a bracketed ISO 8601 timestamp at column one. Events are currently arriving one line at a time, so a single stack trace becomes dozens of events. Which configuration correctly reassembles each record into one event?

選択肢

  1. Leave SHOULD_LINEMERGE at its default and set MAX_TIMESTAMP_LOOKAHEAD to the length of the whole stack trace, so the parser reads far enough into the record to see where it ends inside the window it scans.
  2. Set TRUNCATE to a value larger than the longest stack trace, so the parser stops discarding the continuation lines and keeps them with the first line of each record.
  3. Set SHOULD_LINEMERGE to false and set LINE_BREAKER to a pattern that captures the whitespace immediately before the bracketed timestamp, so the break happens only at the start of a record, which is the point a bracket marks.
  4. Add an ingest-time eval expression that concatenates consecutive events sharing the same host, so the stack trace is rebuilt after the events have been created and the rebuilt event replaces them.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。