Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions
Questions # 51:

Which of the following actions can the eval command perform?

Options:

A.

Remove fields from results.


B.

Create or replace an existing field.


C.

Group transactions by one or more fields.


D.

Save SPL commands to be reused in other searches.


Expert Solution
Questions # 52:

Use this command to use lookup fields in a search and see the lookup fields in the field sidebar.

Options:

A.

inputlookup


B.

lookup


Expert Solution
Questions # 53:

When performing a regular expression (regex) field extraction using the Field Extractor (FX), what happens when the require option is used?

Options:

A.

The regex can no longer be edited.


B.

The field being extracted will be required for all future events.


C.

The events without the required field will not display in searches.


D.

Only events with the required string will be included in the extraction.


Expert Solution
Questions # 54:

If a calculated field has the same name as an extracted field, what happens to the extracted field?

Options:

A.

The calculated field will override the extracted field.


B.

The calculated and extracted fields will be combined.


C.

The calculated field will duplicate the extracted field.


D.

An error will be returned and the search will fail.


Expert Solution
Questions # 55:

When does the CIM add-on apply preconfigured data models to the data?

Options:

A.

Search time


B.

Index time


C.

On a cron schedule


D.

At midnight


Expert Solution
Questions # 56:

Which of the following statements describes the use of the Field Extractor (FX)?

Options:

A.

The Field Extractor automatically extracts all fields at search time.


B.

The Field Extractor uses PERL to extract fields from the raw events.


C.

Fields extracted using the Field Extractor persist as knowledge objects.


D.

Fields extracted using the Field Extractor do not persist and must be defined for each search.


Expert Solution
Questions # 57:

What is the correct syntax to find events associated with a tag?

Options:

A.

tag: < field > = < value >


B.

tags= < value >


C.

tags: < field > = < value >


D.

tag= < value >


Expert Solution
Questions # 58:

Which of the following workflow actions can be executed from search results? (select all that apply)

Options:

A.

GET


B.

POST


C.

LOOKUP


D.

Search


Expert Solution
Questions # 59:

Which of the following statements describe the Common Information Model (CIM)? (select all that apply)

Options:

A.

CIM is a methodology for normalizing data.


B.

CIM can correlate data from different sources.


C.

The Knowledge Manager uses the CIM to create knowledge objects.


D.

CIM is an app that can coexist with other apps on a single Splunk deployment.


Expert Solution
Questions # 60:

A report scheduled to run every 15 mins. but takes 17 mins. to complete is in danger of being_____.

Options:

A.

skipped or deferred


B.

automatically accelerated


C.

deleted


D.

all of the above


Expert Solution
Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions