Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 2

Questions 11

To identify all of the contributing events within a transaction that contains at least one REJECT event, which syntax is correct?

Options:
A.

Index-main | REJECT trans sessionid

B.

Index-main | transaction sessionid | search REJECT

C.

Index=main | transaction sessionid | whose transaction=reject

D.

Index=main | transaction sessionid | where transaction=reject’’

Splunk SPLK-1002 Premium Access
Questions 12

Which of the following statements about tags is true?

Options:
A.

Tags are case insensitive.

B.

Tags are created at index time.

C.

Tags can make your data more understandable.

D.

Tags are searched by using the syntax tag: :

Questions 13

How does a user display a chart in stack mode?

Options:
A.

By using the stack command.

B.

By turning on the Use Trellis Layout option.

C.

By changing Stack Mode in the Format menu.

D.

You cannot display a chart in stack mode, only a timechart.

Questions 14

Which of the following statements describe the search below? (select all that apply)

Index=main I transaction clientip host maxspan=30s maxpause=5s

Options:
A.

Events in the transaction occurred within 5 seconds.

B.

It groups events that share the same clientip and host.

C.

The first and last events are no more than 5 seconds apart.

D.

The first and last events are no more than 30 seconds apart.

Questions 15

Which of the following statements describe calculated fields? (select all that apply)

Options:
A.

Calculated fields can be used in the search bar.

B.

Calculated fields can be based on an extracted field.

C.

Calculated fields can only be applied to host and sourcetype.

D.

Calculated fields are shortcuts for performing calculations using the eval command.

Questions 16

Which of the following search modes automatically returns all extracted fields in the fields sidebar?

Options:
A.

Fast

B.

Smart 

C.

C. Verbose

Questions 17

This function of the stats command allows you to return the middle-most value of field X.

Options:
A.

Median(X)

B.

Eval by X

C.

Fields(X)

D.

Values(X)

Questions 18

Calculated fields can be based on which of the following?

Options:
A.

Tags

B.

Extracted fields

C.

Output fields for a lookup

D.

Fields generated from a search string

Questions 19

It is mandatory for the lookup file to have this for an automatic lookup to work.

Options:
A.

Source type

B.

At least five columns

C.

Timestamp

D.

Input filed

Questions 20

Which of the following describes the I transaction command?

Options:
A.

It is an SPL command that groups at least two events together based on shared values in selected fields.

B.

It allows an exchange of data from one Splunk index to another Splunk index.

C.

It is an SPL command that groups events together with shared values in selected fields.

D.

It allows an exchange of data from one Splunk system to another Splunk system.