ExamGecko
Question list
Search
Search

Question 229 - SPLK-1002 discussion

Report
Export

What commands can be used to group events from one or more data sources?

A.
eval, coalesce
Answers
A.
eval, coalesce
B.
transaction, stats
Answers
B.
transaction, stats
C.
stats, format
Answers
C.
stats, format
D.
top, rare
Answers
D.
top, rare
Suggested answer: B

Explanation:

The transaction and stats commands are two ways to group events from one or more data sources based on common fields or time ranges. The transaction command creates a single event out of a group of related events, while the stats command calculates summary statistics over a group of events. The eval and coalesce commands are used to create or combine fields, not to group events. The format command is used to format the results of a subsearch, not to group events.The top and rare commands are used to rank the most or least common values of a field, not to group events23

1: Splunk Core Certified Power User Track, page 9.2: Splunk Documentation, transaction command.3: Splunk Documentation, stats command.

asked 23/09/2024
Mark Anthony Mondonedo
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first