Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of these is NOT a field that is automatically created with the transaction command?

Options:

A.

maxcount


B.

duration


C.

eventcount


Expert Solution
Questions # 12:

Which workflow action method can be used the action type is set to link?

Options:

A.

GET


B.

PUT


C.

Search


D.

UPDATE


Expert Solution
Questions # 13:

Which of the following statements about tags is true?

Options:

A.

Tags are case insensitive.


B.

Tags are created at index time.


C.

Tags can make your data more understandable.


D.

Tags are searched by using the syntax tag: :


Expert Solution
Questions # 14:

What type of command is eval?

Options:

A.

Streaming in some modes


B.

Report generating


C.

Distributable streaming


D.

Centralized streaming


Expert Solution
Questions # 15:

The fields sidebar does not show________. (Select all that apply.)

Options:

A.

interesting fields


B.

selected fields


C.

all extracted fields


Expert Solution
Questions # 16:

This function of the stats command allows you to return the middle-most value of field X.

Options:

A.

Median(X)


B.

Eval by X


C.

Fields(X)


D.

Values(X)


Expert Solution
Questions # 17:

The macro weekly_sales (2) contains the search string:

index—games I eval Product Sales = $price$ $AmountS01d$

Which of the following will return results?

Options:

A.

‘weekly_sales(3.99, 10) '


B.

‘weekly_sales($3.99$, $10$)


C.

'weekly_sales (3.99, 10)


D.

‘weekly_sales(3)


Expert Solution
Questions # 18:

Consider the following search:

index=web sourcetype=access_combined

The log shows several events that share the same JSESSIONID value (SD470K92802F117). View the events as a group.

From the following list, which search groups events by JSESSIONID?

Options:

A.

index=web sourcetype=access_combined | highlight JSESSIONID | search SD470K92802F117


B.

index=web sourcetype=access_combined | transaction JSESSIONID | search SD470K92802F117


C.

index=web sourcetype=access_combined SD470K92802F117 | table JSESSIONID


D.

index=web sourcetype=access_combined JSESSIONID


Expert Solution
Questions # 19:

Consider the following search:

index=web sourcetype=access_corabined

The log shows several events that share the same jsesszonid value (SD462K101O2F267). View the events as a group.

From the following list, which search groups events by jSSESSIONID?

Options:

A.

index=web sourcetype=access_combined I transaction JSESSZONID I search SD462K101C2F267


B.

index=web sourcetype=access_combined SD462K101O2F267 | table JSESSIONID


C.

index=web sourcetype=access_combined | highlight JSESSIONID | search SD462K101O2F267


D.

index=web sourcetype=access_combined JSESSTONID


Expert Solution
Questions # 20:

We can use the rename command to _____ (Select all that apply.)

Options:

A.

Change indexed fields


B.

Exclude fields from our search results


C.

Extract new fields from our data using regular expressions


D.

Give a field a new name at search time


Expert Solution
Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions