Pass the Splunk Splunk Core Certified Power User SPLK-1002 Questions and answers with CertsForce

Viewing page 8 out of 9 pages
Viewing questions 71-80 out of questions
Questions # 71:

What is the Splunk Common Information Model (CIM)?

Options:

A.

The CIM is a prerequisite that any data source must meet to be successfully onboarded into Splunk.


B.

The CIM provides a methodology to normalize data from different sources and source types.


C.

The CIM defines an ecosystem of apps that can be fully supported by Splunk.


D.

The CIM is a data exchange initiative between software vendors.


Expert Solution
Questions # 72:

Using the export function, you can export search results as __________.( Select all that apply)

Options:

A.

Xml


B.

Json


C.

Html


D.

A php file


Expert Solution
Questions # 73:

What is the correct Boolean order of evaluation for the where command from first to last?

Options:

A.

NOT, Parentheses, OR, AND


B.

AND, Parentheses, NOT, OR


C.

Parentheses, NOT, AND, OR


D.

Parentheses, NOT, OR, AND


Expert Solution
Questions # 74:

The stats command will create a _____________ by default.

Options:

A.

Table


B.

Report


C.

Pie chart


Expert Solution
Questions # 75:

When using | timechart by host, which field is represented in the x-axis?

Options:

A.

date


B.

host


C.

time


D.

_time


Expert Solution
Questions # 76:

When extracting fields, we may choose to use our own regular expressions

Options:

A.

True


B.

False


Expert Solution
Questions # 77:

Which of the following searches will show the number of categoryld used by each host?

Options:

A.

Sourcetype=access_* |sum bytes by host


B.

Sourcetype=access_* |stats sum(categorylD. by host


C.

Sourcetype=access_* |sum(bytes) by host


D.

Sourcetype=access_* |stats sum by host


Expert Solution
Questions # 78:

Which of the following is true about a datamodel that has been accelerated?

Options:

A.

They can be used with Pivot, the | tstats command, or the | datamodel command.


B.

They can still be used in the Pivot tool but only with the accelerate_pivot capability.


C.

They can no longer be used in the Pivot tool.


D.

They can be used with the |tstats command, but will only return that data which has been accelerated.


Expert Solution
Questions # 79:

Which of the following is true about data sets used in the Pivot tool?

Options:

A.

They can only be created from data models.


B.

They can only be created by users with the Admin role.


C.

They can only be created from summary indexes.


D.

They can only be created from saved reports.


Expert Solution
Questions # 80:

Consider the following search:

Index=web sourcetype=access_combined

The log shows several events that share the same JSESSIONID value (SD404K289O2F151). View the events as a group. From the following list, which search groups events by JSESSIONID?

Options:

A.

index=web sourcetype=access_combined SD404K289O2F151 I table JSESSIONID


B.

index=web sourcetype=access_combined JSESSIONID


C.

index=web sourcetype=access_combined I highlight JSESSIONID I search SD404K289O2F151


D.

index-web sourcetype=access_combined I transaction JSESSIONID I search SD404K289O2F151


Expert Solution
Viewing page 8 out of 9 pages
Viewing questions 71-80 out of questions