ExamGecko
Home Home / Splunk / SPLK-1002

Splunk SPLK-1002 Practice Test - Questions Answers, Page 12

Question list
Search
Search

Which command is used to create choropleth maps?

A.
geostats
A.
geostats
Answers
B.
cluster
B.
cluster
Answers
C.
geom
C.
geom
Answers
Suggested answer: C

which of the following are valid options with the chart command

A.
useother
A.
useother
Answers
B.
usenull
B.
usenull
Answers
C.
fillfield
C.
fillfield
Answers
D.
usefiled
D.
usefiled
Answers
Suggested answer: A, B

The gauge command:

A.
creates a single-value visualization
A.
creates a single-value visualization
Answers
B.
allows you to set colored ranges for a single-value visualization
B.
allows you to set colored ranges for a single-value visualization
Answers
C.
creates a radial gauge visualization
C.
creates a radial gauge visualization
Answers
Suggested answer: B

What will you learn from the results of the following search?

sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)

A.
The average time elapsed during each transaction for all transactions
A.
The average time elapsed during each transaction for all transactions
Answers
B.
The average time for each event within each transaction
B.
The average time for each event within each transaction
Answers
C.
The average time between each transaction
C.
The average time between each transaction
Answers
Suggested answer: A

Which of these is NOT a field that is automatically created with the transaction command?

A.
maxcount
A.
maxcount
Answers
B.
duration
B.
duration
Answers
C.
eventcount
C.
eventcount
Answers
Suggested answer: A

How many ways are there to access the Field Extractor Utility?

A.
3
A.
3
Answers
B.
4
B.
4
Answers
C.
1
C.
1
Answers
D.
5
D.
5
Answers
Suggested answer: A

When extracting fields, we may choose to use our own regular expressions

A.
True
A.
True
Answers
B.
False
B.
False
Answers
Suggested answer: A

Field aliases are used to __________ data

A.
clean
A.
clean
Answers
B.
transform
B.
transform
Answers
C.
calculate
C.
calculate
Answers
D.
normalize
D.
normalize
Answers
Suggested answer: D

Complete the search, .... | _____ failure>successes

A.
Search
A.
Search
Answers
B.
Where
B.
Where
Answers
C.
If
C.
If
Answers
D.
Any of the above
D.
Any of the above
Answers
Suggested answer: B

Explanation:

The where command can be used to complete the search below.

... | where failure>successes

The where command is a search command that allows you to filter events based on complex or custom criteri

a. The where command can use any boolean expression or function to evaluate each event and determine whether to keep it or discard it. The where command can also compare fields or perform calculations on fields using operators such as >, <, =, +, -, etc. The where command can be used after any transforming command that creates a table or a chart.

The search string below does the following:

It uses ... to represent any search criteria or commands before the where command.

It uses the where command to filter events based on a comparison between two fields: failure and successes.

It uses the greater than operator (>) to compare the values of failure and successes fields for each event.

It only keeps events where failure is greater than successes.

These kinds of charts represent a series in a single bar with multiple sections

A.
Multi-Series
A.
Multi-Series
Answers
B.
Split-Series
B.
Split-Series
Answers
C.
Omit nulls
C.
Omit nulls
Answers
D.
Stacked
D.
Stacked
Answers
Suggested answer: D

Explanation:

Stacked charts represent a series in a single bar with multiple sections. A chart is a graphical representation of data that shows trends, patterns, or comparisons. A chart can have different types, such as column, bar, line, area, pie, etc. A chart can also have different modes, such as split-series, multi-series, stacked, etc. A stacked chart is a type of chart that shows multiple series in a single bar or area with different sections for each series

Total 291 questions
Go to page: of 30