Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 1 out of 9 pages
Viewing questions 1-10 out of questions
Questions # 1:

What are the two parts of a root event dataset?

Options:

A.

Fields and variables.


B.

Fields and attributes.


C.

Constraints and fields.


D.

Constraints and lookups.


Expert Solution
Questions # 2:

Which delimiters can the Field Extractor (FX) detect? (select all that apply)

Options:

A.

Tabs


B.

Pipes


C.

Spaces


D.

Commas


Expert Solution
Questions # 3:

What is the correct syntax to search for a tag associated with a value on a specific fields?

Options:

A.

Tag-


B.

Tag


C.

Tag=::


D.

Tag::=


Expert Solution
Questions # 4:

Which of the following file formats can be extracted using a delimiter field extraction?

Options:

A.

CSV


B.

PDF


C.

XML


D.

JSON


Expert Solution
Questions # 5:

Which one of the following statements about the search command is true?

Options:

A.

It does not allow the use of wildcards.


B.

It treats field values in a case-sensitive manner.


C.

It can only be used at the beginning of the search pipeline.


D.

It behaves exactly like search strings before the first pipe.


Expert Solution
Questions # 6:

Which of the following statements describes field aliases?

Options:

A.

Field alias names replace the original field name.


B.

Field aliases can be used in lookup file definitions.


C.

Field aliases only normalize data across sources and sourcetypes.


D.

Field alias names are not case sensitive when used as part of a search.


Expert Solution
Questions # 7:

When creating a Search workflow action, which field is required?

Options:

A.

Search string


B.

Data model name


C.

Permission setting


D.

An eval statement


Expert Solution
Questions # 8:

Which of the following statements describe GET workflow actions?

Options:

A.

GET workflow actions must be configured with POST arguments.


B.

Configuration of GET workflow actions includes choosing a sourcetype.


C.

Label names for GET workflow actions must include a field name surrounded by dollar signs.


D.

GET workflow actions can be configured to open the URT link in the current window or in a new window


Expert Solution
Questions # 9:

Which of the following searches will return events contains a tag name Privileged?

Options:

A.

Tag= Priv


B.

Tag= Pri*


C.

Tag= Priv*


D.

Tag= Privileged


Expert Solution
Questions # 10:

A space is an implied _____ in a search string.

Options:

A.

OR


B.

AND


C.

()


D.

NOT


Expert Solution
Viewing page 1 out of 9 pages
Viewing questions 1-10 out of questions