ExamGecko
Question list
Search
Search

Question 166 - SPLK-1002 discussion

Report
Export

When creating a data model, which root dataset requires at least one constraint?

A.
Root transaction dataset
Answers
A.
Root transaction dataset
B.
Root event dataset
Answers
B.
Root event dataset
C.
Root child dataset
Answers
C.
Root child dataset
D.
Root search dataset
Answers
D.
Root search dataset
Suggested answer: B

Explanation:

The correct answer is B. Root event dataset. This is because root event datasets are defined by a constraint that filters out events that are not relevant to the dataset. A constraint for a root event dataset is a simple search that returns a fairly wide range of data, such as sourcetype=access_combined. Without a constraint, a root event dataset would include all the events in the index, which is not useful for data modeling. You can learn more about how to design data models and add root event datasets from the Splunk documentation1. The other options are incorrect because root transaction datasets and root search datasets have different ways of defining their datasets, such as transaction definitions or complex searches, and root child datasets are not a valid type of root dataset.

asked 23/09/2024
Aurelie Touraille Colombo
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first