Splunk SPLK-1002 Practice Test - Questions Answers, Page 28
List of questions
Question 271
When creating an event type, which is allowed in the search string?
Question 272
When using multiple expressions in a single eval command, which delimiter is used?
Question 273
A Splunk app is configured to extract domain names in web service logs and specify them as a field named domain.
What workflow action would return an external IP lookup for the field named domain?
Question 274
Which option of the transaction command would be used to specify the maximum time between events in a transaction?
Question 275
What is needed to define a calculated field?
Question 276
Two separate results tables are being combined using the join command. The outer table has the following values:
The inner table has the following values:
The line of SPL used to join the tables is: join employeeNumber type=outer
How many rows are returned in the new table?
Question 277
Which of the following can be saved as an event type?
Question 278
What is a benefit of installing the Splunk Common Information Model (CIM) add-on?
Question 279
A user wants a table that will show the total revenue made for each product in each sales region. Which would be the correct SPL query to use?
Question 280
How do event types help a user search their data?
Question