Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 4 out of 10 pages
Viewing questions 31-40 out of questions
Questions # 31:

Given the following eval statement:

...| eval fieldl - if(isnotnull(fieldl),fieldl,0), field2 = if(isnull, "NO-VALUE", fieid2)

Which of the following is the equivalent using f ilinull?

Options:

A.

There is no equivalent expression using f ilinull


B.

... t filinull values=(0,"NO-VALUE") fields=(fieldl,field2)


C.

... I filinull value=0 fieldl I fillnull fields


D.

... I fillnull fieldl I filinull value="NO-VALUE" field2


Expert Solution
Questions # 32:

When you mouse over and click to add a search term this (thesE. Boolean operator(s) is(arE. not implied. (Select all that apply).

Options:

A.

OR


B.

( )


C.

AND


D.

NOT


Expert Solution
Questions # 33:

What is the purpose of the fillnull command?

Options:

A.

Replace empty values with a specified value.


B.

Create a new field based on the values in an existing field.


C.

Rename a specific field in the search results.


D.

Replace all values in a specific field with a default value.


Expert Solution
Questions # 34:

What is a limitation of searches generated by workflow actions?

Options:

A.

Searches generated by workflow action cannot use macros.


B.

Searches generated by workflow actions must be less than 256 characters long.


C.

Searches generated by workflow action must run in the same app as the workflow action.


D.

Searches generated by workflow action run with the same permissions as the user running them.


Expert Solution
Questions # 35:

Given the macro definition below, what should be entered into the Name and Arguments fileds to correctly configured the macro?

Question # 35

Options:

A.

The macro name is sessiontracker and the arguments are action, JESSIONID.


B.

The macro name is sessiontracker(2) and the arguments are action, JESSIONID.


C.

The macro name is sessiontracker and the arguments are $action$, $JESSIONID$.


D.

The macro name is sessiontracker(2) and the Arguments are $action$, $JESSIONID$.


Expert Solution
Questions # 36:

Which search string would only return results for an event type called success ful_purchases?

Options:

A.

tag=success ful_purchases


B.

Event Type:: successful purchases


C.

successful_purchases


D.

event type—success ful_purchases


Expert Solution
Questions # 37:

Which knowledge object is used to normalize field names to comply with the Splunk Common Information Model (CIM)?

Options:

A.

Field alias


B.

Event types


C.

Search workflow action


D.

Tags


Expert Solution
Questions # 38:

Which of the following knowledge objects represents the output of an eval expression?

Options:

A.

Eval fields


B.

Calculated fields


C.

Field extractions


D.

Calculated lookups


Expert Solution
Questions # 39:

What is the correct syntax to find events associated with a tag?

Options:

A.

tag:=


B.

tags=


C.

tags:=


D.

tag=


Expert Solution
Questions # 40:

Marty has multiple data sources that contain fields with IP Address values. What knowledge object should he use to normalize the fields so his data is CIM compliant?

Options:

A.

Event type


B.

Field alias


C.

Field extraction


D.

Tag


Expert Solution
Viewing page 4 out of 10 pages
Viewing questions 31-40 out of questions