Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 2

Questions 11

Based on the macro definition shown below, what is the correct way to execute the macro in a search string?

SPLK-1002 Question 11

Options:
A.

Convert_sales (euro, €, 79)”

B.

Convert_sales (euro, €, .79)

C.

Convert_sales ($euro,$€$,s79$

D.

Convert_sales ($euro, $€$,S,79$)

Splunk SPLK-1002 Premium Access
Questions 12

This function of the stats command allows you to identify the number of values a field has.

Options:
A.

max

B.

distinct_count

C.

fields

D.

count

Questions 13

This function of the stats command allows you to return the sample standard deviation of a field.

Options:
A.

stdev

B.

dev

C.

count deviation

D.

by standarddev

Questions 14

Which of the following definitions describes a macro named "samplemacro" that accepts two arguments?

Options:
A.

samplemacro[2]

B.

samplemacro[1,2]

C.

samplemacro(2)

D.

samplemacro(1,2)

Questions 15

Which of the following statements about tags is true?

Options:
A.

Tags are case insensitive.

B.

Tags can make your data more understandable.

C.

Tags are created at index time.

D.

Tags are searched by using the syntax tag :: .

Questions 16

A space is an implied _____ in a search string.

Options:
A.

OR

B.

AND

C.

()

D.

NOT

Questions 17

A data model consists of which three types of datasets?

Options:
A.

Constraint, field, value.

B.

Events, searches, transactions.

C.

Field extraction, regex, delimited.

D.

Transaction, session ID, metadata.

Questions 18

What is a benefit of installing the Splunk Common Information Model (CIM) add-on?

Options:
A.

It permits users to create workflow actions to align with industry standards.

B.

It provides users with a standardized set of field names and tags to normalize data.

C.

It allows users to create 3-D models of their data and export these visualizations.

D.

It enables users to itemize their events based on the results of the Search Job Inspector.

Questions 19

This clause is used to group the output of a stats command by a specific name.

Options:
A.

Rex

B.

As

C.

List

D.

By

Questions 20

Which function should you use with the transaction command to set the maximum total time between the earliest and latest events returned?

Options:
A.

maxpause

B.

endswith

C.

maxduration

D.

maxspan