Pass4itsure > Splunk > Splunk Certifications > SPLK-1002 > SPLK-1002 Online Practice Questions and Answers

SPLK-1002 Online Practice Questions and Answers

Questions 4

Which of the following statements about event types is true? (select all that apply)

A. Event types can be tagged.

B. Event types must include a time range,

C. Event types categorize events based on a search.

D. Event types can be a useful method for capturing and sharing knowledge.

Buy Now
Questions 5

Which of the following statements describes this search?

sourcetype=access_combined I transaction JSESSIONID | timechart avg (duration)

A. This is a valid search and will display a timechart of the average duration, of each transaction event.

B. This is a valid search and will display a stats table showing the maximum pause among transactions.

C. No results will be returned because the transaction command must include the startswith and endswith options.

D. No results will be returned because the transaction command must be the last command used in the search pipeline.

Buy Now
Questions 6

Which of the following statements describe calculated fields? (select all that apply)

A. Calculated fields can be used in the search bar.

B. Calculated fields can be based on an extracted field.

C. Calculated fields can only be applied to host and sourcetype.

D. Calculated fields are shortcuts for performing calculations using the eval command.

Buy Now
Questions 7

Which of the following file formats can be extracted using a delimiter field extraction?

A. CSV

B. PDF

C. XML

D. JSON

Buy Now
Questions 8

What is the correct syntax to search for a tag associated with a value on a specific fields?

A. Tag-

B. Tag

C. Tag=::

D. Tag::=

Buy Now
Questions 9

What do events in a transaction have In common?

A. All events In a transaction must have the same timestamp.

B. All events in a transaction must have the same sourcetype.

C. All events in a transaction must have the exact same set of fields.

D. All events in a transaction must be related by one or more fields.

Buy Now
Questions 10

Which search would limit an "alert" tag to the "host" field?

A. tag=alert

B. host::tag::alert

C. tag==alert

D. tag::host=alert

Buy Now
Questions 11

Which of the following searches would return a report of sales by product-name?

A. chart sales by product_name

B. chart sum(price) as sales by product_name

C. stats sum(price) as sales over product_name

D. timechart list(sales), values(product_name)

Buy Now
Questions 12

Which knowledge Object does the Splunk Common Information Model (CIM) use to normalize data. in addition to field aliases, event types, and tags?

A. Macros

B. Lookups

C. Workflow actions

D. Field extractions

Buy Now
Questions 13

Use this command to use lookup fields in a search and see the lookup fields in the field sidebar.

A. inputlookup

B. lookup

Buy Now
Exam Code: SPLK-1002
Exam Name: Splunk Core Certified Power User
Last Update: Apr 11, 2024
Questions: 239
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$45.99

VCE

$49.99

PDF + VCE

$59.99