ExamGecko
Home / Splunk / SPLK-1002
Ask Question

Splunk SPLK-1002 Practice Test - Questions Answers, Page 15

Question list
Search

Question 141

Report
Export
Collapse

A data model can consist of what three types of datasets?

Pivot, searches, and events.
Pivot, searches, and events.
Pivot, events, and transactions.
Pivot, events, and transactions.
Searches, transactions, and pivot.
Searches, transactions, and pivot.
Events, searches, and transactions.
Events, searches, and transactions.
Suggested answer: D
asked 23/09/2024
Domenico D'Angelo
40 questions

Question 142

Report
Export
Collapse

When is a GET workflow action needed?

To send field values to an external resource.
To send field values to an external resource.
To retrieve information from an external resource.
To retrieve information from an external resource.
To use field values to perform a secondary search.
To use field values to perform a secondary search.
To define how events flow from forwarders to indexes.
To define how events flow from forwarders to indexes.
Suggested answer: B
asked 23/09/2024
Pedram Habibi
37 questions

Question 143

Report
Export
Collapse

Which command can include both an over and a by clause to divide results into sub-groupings?

chart
chart
stats
stats
xyseries
xyseries
transaction
transaction
Suggested answer: A
asked 23/09/2024
carlos salgado
40 questions

Question 144

Report
Export
Collapse

A user wants to create a new field alias for a field that appears in two sourcetypes.

How many field aliases need to be created?

One.
One.
Two.
Two.
It depends on whether the original fields have the same name.
It depends on whether the original fields have the same name.
It depends on whether the two sourcetypes are associated with the same index.
It depends on whether the two sourcetypes are associated with the same index.
Suggested answer: B
asked 23/09/2024
Moshope Salami
45 questions

Question 145

Report
Export
Collapse

In the following eval statement, what is the value of description if the status is 503? index=main | eval description=case(status==200, 'OK', status==404, 'Not found', status==500, 'Internal Server Error')

The description field would contain no value.
The description field would contain no value.
The description field would contain the value 0.
The description field would contain the value 0.
The description field would contain the value 'Internal Server Error'.
The description field would contain the value 'Internal Server Error'.
This statement would produce an error in Splunk because it is incomplete.
This statement would produce an error in Splunk because it is incomplete.
Suggested answer: A

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/ConditionalFunctions

asked 23/09/2024
samresh mahata
36 questions

Question 146

Report
Export
Collapse

In which Settings section are macros defined?

Fields
Fields
Tokens
Tokens
Advanced Search
Advanced Search
Searches, Reports, Alerts
Searches, Reports, Alerts
Suggested answer: C
asked 23/09/2024
KHALID ALSHAHRANI
46 questions

Question 147

Report
Export
Collapse

Which of the following statements describes calculated fields?

Calculated fields are only used on fields added by lookups.
Calculated fields are only used on fields added by lookups.
Calculated fields are a shortcut for repetitive and complex eval commands.
Calculated fields are a shortcut for repetitive and complex eval commands.
Calculated fields are a shortcut for repetitive and complex calc commands.
Calculated fields are a shortcut for repetitive and complex calc commands.
Calculated fields automatically calculate the simple moving average for indexed fields.
Calculated fields automatically calculate the simple moving average for indexed fields.
Suggested answer: B
asked 23/09/2024
Chakour BOURAIMA
33 questions

Question 148

Report
Export
Collapse

Which of the following is one of the pre-configured data models included in the Splunk Common Information Model (CIM) add-on?

Access
Access
Accounting
Accounting
Authorization
Authorization
Authentication
Authentication
Suggested answer: D
asked 23/09/2024
Kimon Pope
32 questions

Question 149

Report
Export
Collapse

What happens when a user edits the regular expression (regex) field extraction generated in the Field Extractor (FX)?

There is a limit to the number of fields that can be extracted.
There is a limit to the number of fields that can be extracted.
The user is unable to preview the extractions.
The user is unable to preview the extractions.
The extraction is added at index time.
The extraction is added at index time.
The user is unable to return to the automatic field extraction workflow.
The user is unable to return to the automatic field extraction workflow.
Suggested answer: A
asked 23/09/2024
Islam Fadel
32 questions

Question 150

Report
Export
Collapse

Consider the following search:

Index=web sourcetype=access_combined

The log shows several events that share the same JSESSIONID value (SD404K289O2F151). View the events as a group. From the following list, which search groups events by JSESSIONID?

index=web sourcetype=access_combined SD404K289O2F151 I table JSESSIONID
index=web sourcetype=access_combined SD404K289O2F151 I table JSESSIONID
index=web sourcetype=access_combined JSESSIONID <SD404K289O2F151>
index=web sourcetype=access_combined JSESSIONID <SD404K289O2F151>
index=web sourcetype=access_combined I highlight JSESSIONID I search SD404K289O2F151
index=web sourcetype=access_combined I highlight JSESSIONID I search SD404K289O2F151
index-web sourcetype=access_combined I transaction JSESSIONID I search SD404K289O2F151
index-web sourcetype=access_combined I transaction JSESSIONID I search SD404K289O2F151
Suggested answer: B
asked 23/09/2024
hajar mechrany
30 questions
Total 291 questions
Go to page: of 30