Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 2 out of 10 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following is true about Pivot?

Options:

A.

Users can save reports from Pivot.


B.

Users cannot share visualizations created with Pivot.


C.

Users must use SPL to find events in a Pivot.


D.

Users cannot create visualizations with Pivot.


Expert Solution
Questions # 12:

Which of the following does not describe how to create an event type?

Options:

A.

Run a search string and use the Save As button.


B.

Use the New Event Type button from the Settings menu.


C.

Use the Field Extractor to analyze and use the Save As button.


D.

Select search criteria within the Event Type Builder.


Expert Solution
Questions # 13:

Which of the following is true about data sets used in the Pivot tool?

Options:

A.

They can only be created from data models.


B.

They can only be created by users with the Admin role.


C.

They can only be created from summary indexes.


D.

They can only be created from saved reports.


Expert Solution
Questions # 14:

This clause is used to group the output of a stats command by a specific name.

Options:

A.

Rex


B.

As


C.

List


D.

By


Expert Solution
Questions # 15:

What is the correct Boolean order of evaluation for the where command from first to last?

Options:

A.

NOT, Parentheses, OR, AND


B.

AND, Parentheses, NOT, OR


C.

Parentheses, NOT, AND, OR


D.

Parentheses, NOT, OR, AND


Expert Solution
Questions # 16:

When using the transaction command, how are evicted transactions identified?

Options:

A.

Closed_txn field is set to o, or false.


B.

Max_txn field is set to O, or false.


C.

Txn_field is set to 1, or true.


D.

open_txn field is set to 1, or true.


Expert Solution
Questions # 17:

Which of the following fields should be normalized using the Splunk Common Information Model (CIM) based on their relationship?

Options:

A.

src_ip, dest_ip


B.

src_ip, source_ip


C.

index, sourcetype


D.

src_ip, src_port


Expert Solution
Questions # 18:

Which of the following knowledge objects can reference field aliases?

Options:

A.

Calculated fields, lookups, event types, and tags.


B.

Calculated fields and tags only.


C.

Calculated fields and event types only.


D.

Calculated fields, lookups, event types, and extracted fields.


Expert Solution
Questions # 19:

What does the fillnull command replace null values with, it the value argument is not specified?

Options:

A.

0


B.

N/A


C.

NaN


D.

NULL


Expert Solution
Questions # 20:

Which of the following knowledge objects represents the output of an eval expression?

Options:

A.

Eval fields


B.

Calculated fields


C.

Field extractions


D.

Calculated lookups


Expert Solution
Viewing page 2 out of 10 pages
Viewing questions 11-20 out of questions