Certbus > Splunk > Splunk Certifications > SPLK-1002 > SPLK-1002 Online Practice Questions and Answers

SPLK-1002 Online Practice Questions and Answers

Questions 4

When should you use the transaction command instead of the scats command?

A. When you need to group on multiple values.

B. When duration is irrelevant in search results. .

C. When you have over 1000 events in a transaction.

D. When you need to group based on start and end constraints.

Browse 239 Q&As
Questions 5

What is the relationship between data models and pivots?

A. Data models provide the datasets for pivots.

B. Pivots and data models have no relationship.

C. Pivots and data models are the same thing.

D. Pivots provide the datasets for data models.

Browse 239 Q&As
Questions 6

How does a user display a chart in stack mode?

A. By using the stack command.

B. By turning on the Use Trellis Layout option.

C. By changing Stack Mode in the Format menu.

D. You cannot display a chart in stack mode, only a timechart.

Browse 239 Q&As
Questions 7

Which of the following knowledge objects represents the output of an eval expression?

A. Eval fields

B. Calculated fields

C. Field extractions

D. Calculated lookups

Browse 239 Q&As
Questions 8

Which of the following file formats can be extracted using a delimiter field extraction?

A. CSV

B. PDF

C. XML

D. JSON

Browse 239 Q&As
Questions 9

Which of the following eval command function is valid?

A. Int ()

B. Count ( )

C. Print ()

D. Tostring ()

Browse 239 Q&As
Questions 10

Which of the following statements describes the use of the Field Extractor (FX)?

A. The Field Extractor automatically extracts all fields at search time.

B. The Field Extractor uses PERL to extract fields from the raw events.

C. Fields extracted using the Field Extractor persist as knowledge objects.

D. Fields extracted using the Field Extractor do not persist and must be defined for each search.

Browse 239 Q&As
Questions 11

How is an event type created from the search window? (select all that apply)

A. In the top right corner, click Save As > Event Type.

B. In an event's detail dropdown, click Event Actions > Build Event Type.

C. Edit eventtypes.conf and add a new stanza.

D. Add | eventtype to the SPL and execute the search.

Browse 239 Q&As
Questions 12

Select this in the fields sidebar to automatically pipe you search results to the rare command

A. events with this field

B. rare values

C. top values by time

D. top values

Browse 239 Q&As
Questions 13

Which workflow uses field values to perform a secondary search?

A. POST

B. Action

C. Search D. Sub-Search

Browse 239 Q&As
Questions 14

Which is not a comparison operator in Splunk

A. <=

B. =

C. !=

D. >

E. ?=

Browse 239 Q&As
Questions 15

Splunk alerts can be based on search that run______. (Select all that apply.)

A. in real-time

B. on a regular schedule

C. and have no matching events

Browse 239 Q&As
Questions 16

In the Field Extractor, when would the regular expression method be used?

A. When events contain JSON data.

B. When events contain comma-separated data.

C. When events contain unstructured data.

D. When events contain table-based data.

Browse 239 Q&As
Questions 17

Which tool uses data models to generate reports and dashboard panels without using SPL?

A. Visualization tab

B. Pivot

C. Datasets

D. splunk CIM

Browse 239 Q&As
Questions 18

When using the transaction command, what does the argument maxspan do?

A. Sets the maximum total time between events in a transaction.

B. Sets the maximum length of all events within a transaction.

C. Sets the maximum total time between the earliest and latest events in a transaction.

D. Sets the maximum length that any single event can reach to be included in the transaction.

Browse 239 Q&As
Exam Code: SPLK-1002
Exam Name: Splunk Core Certified Power User
Last Update: Apr 25, 2024
Questions: 239 Q&As

PDF

$45.99

VCE

$49.99

PDF + VCE

$59.99