Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 2

Questions 11

These allow you to categorize events based on search terms.

Select your answer.

Options:
A.

Groups

B.

Event Types

C.

Macros

D.

Tags

Splunk SPLK-1002 Premium Access
Questions 12

Which of the following is true about data model attributes?

Options:
A.

They cannot be created within the data model.

B.

They can only be added into a root search dataset.

C.

They cannot be edited if inherited from a parent dataset.

D.

They can be added to a dataset from search time field extractions.

Questions 13

In which of the following scenarios is an event type more effective than a saved search?

Options:
A.

When a search should always include the same time range.

B.

When a search needs to be added to other users' dashboards.

C.

When the search string needs to be used in future searches.

D.

When formatting needs to be included with the search string.

Questions 14

Field aliases are used to __________ data

Options:
A.

clean

B.

transform

C.

calculate

D.

normalize

Questions 15

Which of the following describes the I transaction command?

Options:
A.

It is an SPL command that groups at least two events together based on shared values in selected fields.

B.

It allows an exchange of data from one Splunk index to another Splunk index.

C.

It is an SPL command that groups events together with shared values in selected fields.

D.

It allows an exchange of data from one Splunk system to another Splunk system.

Questions 16

Which of the following data models are included in the Splunk Common Information Model (CIM) add-on? (select all that apply)

Options:
A.

User permissions

B.

Alerts

C.

Databases

D.

Email

Questions 17

In what order arc the following knowledge objects/configurations applied?

Options:
A.

Field Aliases, Field Extractions, Lookups

B.

Field Extractions, Field Aliases, Lookups

C.

Field Extractions, Lookups, Field Aliases

D.

Lookups, Field Aliases, Field Extractions

Questions 18

After manually editing; a regular expression (regex), which of the following statements is true?

Options:
A.

Changes made manually can be reverted in the Field Extractor (FX) UI.

B.

It is no longer possible to edit the field extraction in the Field Extractor (FX) UI.

C.

It is not possible to manually edit a regular expression (regex) that was created using the Field Extractor (FX) UI.

D.

The Field Extractor (FX) UI keeps its own version of the field extraction in addition to the one that was manually edited.

Questions 19

Which of the following can be saved as an event type?

Options:
A.

index-server_472 sourcetype-BETA_494 code-488 I stats count by code

B.

index=server_472 sourcetype=BETA_494 code=488 [I inputlookup append=t servercode.csv]

C.

index=server_472 sourcetype=BETA_494 code=488 I stats where code > 200

D.

index=server_472 sourcetype=BETA_494 code-488

Questions 20

In this search, __________ will appear on the y-axis. SEARCH: sourcetype=access_combined status!=200 | chart count over host

Options:
A.

status

B.

host

C.

count