ExamGecko
Home / Splunk / SPLK-1002 / List of questions
Ask Question

Splunk SPLK-1002 Practice Test - Questions Answers, Page 12

Question list
Search

Question 111

Report
Export
Collapse

Which command is used to create choropleth maps?

geostats
geostats
cluster
cluster
geom
geom
Suggested answer: C
asked 23/09/2024
Van Raoul Datuin
32 questions

Question 112

Report
Export
Collapse

which of the following are valid options with the chart command

useother
useother
usenull
usenull
fillfield
fillfield
usefiled
usefiled
Suggested answer: A, B
asked 23/09/2024
Abheesh Vijayan
24 questions

Question 113

Report
Export
Collapse

The gauge command:

creates a single-value visualization
creates a single-value visualization
allows you to set colored ranges for a single-value visualization
allows you to set colored ranges for a single-value visualization
creates a radial gauge visualization
creates a radial gauge visualization
Suggested answer: B
asked 23/09/2024
Victor Cantu
36 questions

Question 114

Report
Export
Collapse

What will you learn from the results of the following search?

sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)

The average time elapsed during each transaction for all transactions
The average time elapsed during each transaction for all transactions
The average time for each event within each transaction
The average time for each event within each transaction
The average time between each transaction
The average time between each transaction
Suggested answer: A
asked 23/09/2024
Priyantha Perea
40 questions

Question 115

Report
Export
Collapse

Which of these is NOT a field that is automatically created with the transaction command?

maxcount
maxcount
duration
duration
eventcount
eventcount
Suggested answer: A
asked 23/09/2024
Mark Singer
42 questions

Question 116

Report
Export
Collapse

How many ways are there to access the Field Extractor Utility?

3
3
4
4
1
1
5
5
Suggested answer: A
asked 23/09/2024
ayodele fakayode
35 questions

Question 117

Report
Export
Collapse

When extracting fields, we may choose to use our own regular expressions

True
True
False
False
Suggested answer: A
asked 23/09/2024
Massimiliano Parisi
39 questions

Question 118

Report
Export
Collapse

Field aliases are used to __________ data

clean
clean
transform
transform
calculate
calculate
normalize
normalize
Suggested answer: D
asked 23/09/2024
Lionel Fitzgerald Gweth
44 questions

Question 119

Report
Export
Collapse

Complete the search, .... | _____ failure>successes

Search
Search
Where
Where
If
If
Any of the above
Any of the above
Suggested answer: B

Explanation:

The where command can be used to complete the search below.

... | where failure>successes

The where command is a search command that allows you to filter events based on complex or custom criteri

a. The where command can use any boolean expression or function to evaluate each event and determine whether to keep it or discard it. The where command can also compare fields or perform calculations on fields using operators such as >, <, =, +, -, etc. The where command can be used after any transforming command that creates a table or a chart.

The search string below does the following:

It uses ... to represent any search criteria or commands before the where command.

It uses the where command to filter events based on a comparison between two fields: failure and successes.

It uses the greater than operator (>) to compare the values of failure and successes fields for each event.

It only keeps events where failure is greater than successes.

asked 23/09/2024
Marcio Lizarbe
40 questions

Question 120

Report
Export
Collapse

These kinds of charts represent a series in a single bar with multiple sections

Multi-Series
Multi-Series
Split-Series
Split-Series
Omit nulls
Omit nulls
Stacked
Stacked
Suggested answer: D

Explanation:

Stacked charts represent a series in a single bar with multiple sections. A chart is a graphical representation of data that shows trends, patterns, or comparisons. A chart can have different types, such as column, bar, line, area, pie, etc. A chart can also have different modes, such as split-series, multi-series, stacked, etc. A stacked chart is a type of chart that shows multiple series in a single bar or area with different sections for each series

asked 23/09/2024
Udara Somachandra
49 questions
Total 299 questions
Go to page: of 30