Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 3 out of 9 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which of the following statements describes macros?

Options:

A.

A macro is a reusable search string that must contain the full search.


B.

A macro is a reusable search string that must have a fixed time range.


C.

A macro Is a reusable search string that may have a flexible time range.


D.

A macro Is a reusable search string that must contain only a portion of the search.


Expert Solution
Questions # 22:

What happens to the original field name when a field alias is created?

Options:

A.

The original field name is not affected by the creation of a field alias.


B.

The original field name is replaced by the field alias within the index.


C.

The original field name is italicized to indicate that it is not an alias.


D.

The original field name still exists in the index but is not visible to the user at search time.


Expert Solution
Questions # 23:

What is the Splunk Common Information Model (CIM)?

Options:

A.

The CIM is a prerequisite that any data source must meet to be successfully onboarded into Splunk.


B.

The CIM provides a methodology to normalize data from different sources and source types.


C.

The CIM defines an ecosystem of apps that can be fully supported by Splunk.


D.

The CIM is a data exchange initiative between software vendors.


Expert Solution
Questions # 24:

Which of the following options will define the first event in a transaction?

Options:

A.

startswith


B.

with


C.

startingwith


D.

firstevent


Expert Solution
Questions # 25:

Which command is used to create choropleth maps?

Options:

A.

geostats


B.

cluster


C.

geom


Expert Solution
Questions # 26:

In what order arc the following knowledge objects/configurations applied?

Options:

A.

Field Aliases, Field Extractions, Lookups


B.

Field Extractions, Field Aliases, Lookups


C.

Field Extractions, Lookups, Field Aliases


D.

Lookups, Field Aliases, Field Extractions


Expert Solution
Questions # 27:

Which of the following statements describe calculated fields? (select all that apply)

Options:

A.

Calculated fields can be used in the search bar.


B.

Calculated fields can be based on an extracted field.


C.

Calculated fields can only be applied to host and sourcetype.


D.

Calculated fields are shortcuts for performing calculations using the eval command.


Expert Solution
Questions # 28:

Which of the following statements describes an event type?

Options:

A.

A log level measurement: info, warn, error.


B.

A knowledge object that is applied before fields are extracted.


C.

A field for categorizing events based on a search string.


D.

Either a log, a metric, or a trace.


Expert Solution
Questions # 29:

This is what Splunk uses to categorize the data that is being indexed.

Options:

A.

sourcetype


B.

index


C.

source


D.

host


Expert Solution
Questions # 30:

Which of the following objects can a calculated field use as a source?

Options:

A.

An alias of a field.


B.

A field added by an automatic lookup.


C.

The tag field.


D.

The eventtype field.


Expert Solution
Viewing page 3 out of 9 pages
Viewing questions 21-30 out of questions