What is needed to define a calculated field?
A user wants to create a workflow action that will retrieve a specific field value from an event and run a search in a new browser window
in the user's Splunk instance. What kind of workflow action should they create?
When defining a macro, what are the required elements?
__________ datasets can be added to root dataset to narrow down the search