Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions
Questions # 51:

Which of the following searches would return a report of sales by product-name?

Options:

A.

chart sales by product_name


B.

chart sum(price) as sales by product_name


C.

stats sum(price) as sales over product_name


D.

timechart list(sales), values(product_name)


Expert Solution
Questions # 52:

In which Settings section are macros defined?

Options:

A.

Fields


B.

Tokens


C.

Advanced Search


D.

Searches, Reports, Alerts


Expert Solution
Questions # 53:

Consider the the following search run over a time range of last 7 days:

index=web sourcetype=access_conbined | timechart avg(bytes) by product_nane

Which option is used to change the default time span so that results are grouped into 12 hour intervals?

Options:

A.

span=12h


B.

timespan=12h


C.

span=12


D.

timespan=12


Expert Solution
Questions # 54:

When should the delimiter method be used in the Field Extractor?

Options:

A.

When the events do not have the correct permissions set.


B.

When the events are separated by a consistent character or set of characters.


C.

When the events need a regular expression to define the matching pattern.


D.

When the events need to be calculated using special characters.


Expert Solution
Questions # 55:

A macro has another macro nested within it, and this inner macro requires an argument. How can the user pass this argument into the SPL?

Options:

A.

An argument can be passed through the outer macro.


B.

An argument can be passed to the outer macro by nesting parentheses.


C.

There is no way to pass an argument to the inner macro.


D.

An argument can be passed to the inner macro by nesting parentheses.


Expert Solution
Questions # 56:

Which of the following statements describes the command below (select all that apply)

Sourcetype=access_combined | transaction JSESSIONID

Options:

A.

An additional filed named maxspan is created.


B.

An additional field named duration is created.


C.

An additional field named eventcount is created.


D.

Events with the same JSESSIONID will be grouped together into a single event.


Expert Solution
Questions # 57:

Which of the following statements describe data model acceleration? (select all that apply)

Options:

A.

Root events cannot be accelerated.


B.

Accelerated data models cannot be edited.


C.

Private data models cannot be accelerated.


D.

You must have administrative permissions or the accelerate_dacamodel capability to accelerate a data model.


Expert Solution
Questions # 58:

The limit attribute will___________.

Options:

A.

override default of 10


B.

only work with top command


C.

override default of 20


D.

override default of 15


Expert Solution
Questions # 59:

Which delimiters can the Field Extractor (FX) detect? (select all that apply)

Options:

A.

Tabs


B.

Pipes


C.

Spaces


D.

Commas


Expert Solution
Questions # 60:

Where are the descriptions of the data models that come with the Splunk Common Information Model (CIM) Add-on documented?

Options:

A.

Search and reporting user manual.


B.

CIM Add-on manual.


C.

Pivot users manual.


D.

Datamodel command reference guide.


Expert Solution
Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions