Splunk Core Certified User — Question 203

NOT status = 100:

Answer options

Correct answer: C

Explanation

The correct answer, C, accurately describes that the query will return events where the status is not 100 and also includes events that lack the status field entirely. Option A is incorrect as it doesn't specify the conditions of the status field. Option B is partially correct but fails to mention events without the status field.