Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 6 out of 9 pages
Viewing questions 51-60 out of questions
Questions # 51:

Which of the following can be saved as an event type?

Options:

A.

index=server_485 sourcetype=BETA_726 code=917 ['inputlookup append=t servercode.csv]


B.

index=server_485 sourcetype=BETA_726 code=917 | stats where code > 200


C.

index=server_485 sourcetype=BETA_726 code=917


D.

index=server_485 sourcetype=BETA_726 code=917 | stats count by code


Expert Solution
Questions # 52:

Which workflow action method can be used the action type is set to link?

Options:

A.

GET


B.

PUT


C.

Search


D.

UPDATE


Expert Solution
Questions # 53:

The eval command 'if' function requires the following three arguments (in order):

Options:

A.

Boolean expression, result if true, result if false


B.

Result if true, result if false, boolean expression


C.

Result if false, result if true, boolean expression


D.

Boolean expression, result if false, result if true


Expert Solution
Questions # 54:

Which command can include both an over and a by clause to divide results into sub-groupings?

Options:

A.

chart


B.

stats


C.

xyseries


D.

transaction


Expert Solution
Questions # 55:

Which of the following definitions describes a macro named "samplemacro" that accepts two arguments?

Options:

A.

Examplemacro [1,2]


B.

samplemacro(1,2)


C.

u amp -CJEUCXG (2)


D.

samplemacro[2]


Expert Solution
Questions # 56:

Which of the following is a function of the Splunk Common Information Model (CIM)?

Options:

A.

Normalizing data across a Splunk deployment.


B.

Providing templates for reports and dashboards.


C.

Algorithmically shifting events to other indexes.


D.

Reingesting previously indexed data with new field names.


Expert Solution
Questions # 57:

What information must be included when using the datamodel command?

Options:

A.

status field


B.

Multiple indexes


C.

Data model field name.


D.

Data model dataset name.


Expert Solution
Questions # 58:

Which of the following can be saved as an event type?

Options:

A.

index=server_48 sourcetype=BETA_881 code=220


B.

index=server_48 sourcetype=BETA_881 code=220 | stats count by code


C.

index=server_48 sourcetype=BETA_881 code=220 | inputlookup append=t servercode.csv


D.

index=server_48 sourcetype=BETA_881 code=220 | stats where code > 220


Expert Solution
Questions # 59:

A data model can consist of what three types of datasets?

Options:

A.

Pivot, searches, and events.


B.

Pivot, events, and transactions.


C.

Searches, transactions, and pivot.


D.

Events, searches, and transactions.


Expert Solution
Questions # 60:

Which statement is true?

Options:

A.

Pivot is used for creating datasets.


B.

Data models are randomly structured datasets.


C.

Pivot is used for creating reports and dashboards.


D.

In most cases, each Splunk user will create their own data model.


Expert Solution
Viewing page 6 out of 9 pages
Viewing questions 51-60 out of questions