Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 2 out of 10 pages
Viewing questions 11-20 out of questions
Questions # 11:

What information must be included when using the datamodel command?

Options:

A.

status field


B.

Multiple indexes


C.

Data model field name.


D.

Data model dataset name.


Expert Solution
Questions # 12:

Which of the following knowledge objects can reference field aliases?

Options:

A.

Calculated fields, lookups, event types, and tags.


B.

Calculated fields and tags only.


C.

Calculated fields and event types only.


D.

Calculated fields, lookups, event types, and extracted fields.


Expert Solution
Questions # 13:

These kinds of charts represent a series in a single bar with multiple sections

Options:

A.

Multi-Series


B.

Split-Series


C.

Omit nulls


D.

Stacked


Expert Solution
Questions # 14:

Which of the following statements describe the search below? (select all that apply)

Index=main I transaction clientip host maxspan=30s maxpause=5s

Options:

A.

Events in the transaction occurred within 5 seconds.


B.

It groups events that share the same clientip and host.


C.

The first and last events are no more than 5 seconds apart.


D.

The first and last events are no more than 30 seconds apart.


Expert Solution
Questions # 15:

Which workflow action method can be used the action type is set to link?

Options:

A.

GET


B.

PUT


C.

Search


D.

UPDATE


Expert Solution
Questions # 16:

Which of the following is one of the pre-configured data models included in the Splunk Common Information Model (CIM) add-on?

Options:

A.

Access


B.

Accounting


C.

Authorization


D.

Authentication


Expert Solution
Questions # 17:

A Splunk app is configured to extract domain names in web service logs and specify them as a field named domain.

What workflow action would return an external IP lookup for the field named domain?

Options:

A.

POST


B.

PUT


C.

GET


D.

Search


Expert Solution
Questions # 18:

What approach is recommended when using the Splunk Common Information Model (CIM) add-on to normalize data?

Options:

A.

Consult the CIM data model reference tables.


B.

Run a search using the authentication command.


C.

Consult the CIM event type reference tables.


D.

Run a search using the correlation command.


Expert Solution
Questions # 19:

What does the fillnull command do in this search?

index=main sourcetype=http:log | fillnull value="Unknown" src

Options:

A.

Set the values of the src field to null when it is "Unknown".


B.

Set all fields that are null to "Unknown".


C.

Set the values of the src field to "Unknown" if it is null.


D.

Set all fields with the value of "Unknown" to null.


Expert Solution
Questions # 20:

Where are the results of eval commands stored?

Options:

A.

In a field.


B.

In an index.


C.

In a KV Store.


D.

In a database.


Expert Solution
Viewing page 2 out of 10 pages
Viewing questions 11-20 out of questions