When should transaction be used?
When using multiple expressions in a single eval command, which delimiter is used?
Which of the following describes this search?
New Search
'third_party_outages(EMEA,-24h)'
A Splunk app is configured to extract domain names in web service logs and specify them as a field named domain.
What workflow action would return an external IP lookup for the field named domain?