Splunk SPLK-1002 Practice Test - Questions Answers, Page 23
List of questions
Question 221
Which tool uses data models to generate reports and dashboard panels without using SPL?
Question 222
Which knowledge object is used to normalize field names to comply with the Splunk Common Information Model (CIM)?
Question 223
How is an event type created from the search window? (select all that apply)
Question 224
Consider the following search:
index=web sourcetype=access_corabined
The log shows several events that share the same jsesszonid value (SD462K101O2F267). View the events as a group.
From the following list, which search groups events by jSSESSIONID?
Question 225
Which of the following is true about the Splunk Common Information Model (CIM)?
Question 226
When defining a macro, what are the required elements?
Question 227
Which of the following expressions could be used to create a calculated field called gigabytes?
Question 228
Consider the the following search run over a time range of last 7 days:
index=web sourcetype=access_conbined | timechart avg(bytes) by product_nane
Which option is used to change the default time span so that results are grouped into 12 hour intervals?
Question 229
What commands can be used to group events from one or more data sources?
Question 230
Tags can reference which of the following knowledge objects?
Question