Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which of the following statements describes this search?

sourcetype=access_combined I transaction JSESSIONID | timechart avg (duration)

Options:

A.

This is a valid search and will display a timechart of the average duration, of each transaction event.


B.

This is a valid search and will display a stats table showing the maximum pause among transactions.


C.

No results will be returned because the transaction command must include the startswith and endswith options.


D.

No results will be returned because the transaction command must be the last command used in the search pipeline.


Expert Solution
Questions # 32:

When using timechart, how many fields can be listed after a by clause?

Options:

A.

because timechart doesn't support using a by clause.


B.

because _time is already implied as the x-axis.


C.

because one field would represent the x-axis and the other would represent the y-axis.


D.

There is no limit specific to timechart.


Expert Solution
Questions # 33:

Given the macro definition below, what should be entered into the Name and Arguments fileds to correctly configured the macro?

Question # 33

Options:

A.

The macro name is sessiontracker and the arguments are action, JESSIONID.


B.

The macro name is sessiontracker(2) and the arguments are action, JESSIONID.


C.

The macro name is sessiontracker and the arguments are $action$, $JESSIONID$.


D.

The macro name is sessiontracker(2) and the Arguments are $action$, $JESSIONID$.


Expert Solution
Questions # 34:

A field alias has been created based on an original field. A search without any transforming commands is then executed in Smart Mode. Which field name appears in the results?

Options:

A.

Both will appear in the All Fields list, but only if the alias is specified in the search.


B.

Both will appear in the Interesting Fields list, but only if they appear in at least 20 percent of events.


C.

The original field only appears in All Fields list and the alias only appears in the Interesting Fields list.


D.

The alias only appears in the All Fields list and the original field only appears in the Interesting Fields list.


Expert Solution
Questions # 35:

The Field Extractor (FX) is used to extract a custom field. A report can be created using this custom field. The created report can then be shared with other people in the organization. If another person in the organization runs the shared report and no results are returned, why might this be? (select all that apply)

Options:

A.

Fast mode is enabled.


B.

The dashboard is private.


C.

The extraction is private-


D.

The person in the organization running the report does not have access to the index.


Expert Solution
Questions # 36:

Which are valid ways to create an event type? (select all that apply)

Options:

A.

By using the searchtypes command in the search bar.


B.

By editing the event_type stanza in the props.conf file.


C.

By going to the Settings menu and clicking Event Types > New.


D.

By selecting an event in search results and clicking Event Actions > Build Event Type.


Expert Solution
Questions # 37:

What functionality does the Splunk Common Information Model (CIM) rely on to normalize fields with different names?

Options:

A.

Macros.


B.

Field aliases.


C.

The rename command.


D.

CIM does not work with different names for the same field.


Expert Solution
Questions # 38:

When using the Field Extractor (FX), which of the following delimiters will work? (select all that apply)

Options:

A.

Tabs


B.

Pipes


C.

Colons


D.

Spaces


Expert Solution
Questions # 39:

In which of the following scenarios is an event type more effective than a saved search?

Options:

A.

When a search should always include the same time range.


B.

When a search needs to be added to other users' dashboards.


C.

When the search string needs to be used in future searches.


D.

When formatting needs to be included with the search string.


Expert Solution
Questions # 40:

Data model are composed of one or more of which of the following datasets? (select all that apply.)

Options:

A.

Events datasets


B.

Search datasets


C.

Transaction datasets


D.

Any child of event, transaction, and search datasets


Expert Solution
Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions