Which of the following is a valid event action in Splunk?
A report named "Linux logins" populates a summary index with the search string sourcetype=linux_secure | sitop src_ip user. Which of the following correctly searches against the summary index for this data?
What are the four types of event actions?
What is the correct hierarchy of XML elements in a dashboard panel?