Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 4

Questions 31

Which knowledge object is used to normalize field names to comply with the Splunk Common Information Model (CIM)?

Options:
A.

Field alias

B.

Event types

C.

Search workflow action

D.

Tags

Splunk SPLK-1002 Premium Access
Questions 32

When using the transaction command, what is the assigned timestamp for each of the resulting transactions?

Options:
A.

The timestamp of the event search time execution.

B.

The timestamp of the earliest event.

C.

The difference between the earliest and latest event.

D.

The timestamp of the most recent event.

Questions 33

Which of the following statements are true for this search? (Select all that apply.) SEARCH: sourcetype=access* |fields action productld status

Options:
A.

is looking for all events that include the search terms: fields AND action AND productld AND status

B.

users the table command to improve performance

C.

limits the fields are extracted

D.

returns a table with 3 columns

Questions 34

When does the CIM add-on apply preconfigured data models to the data?

Options:
A.

Search time

B.

Index time

C.

On a cron schedule

D.

At midnight

Questions 35

When using the transaction command, what does the argument maxspan do?

Options:
A.

Sets the maximum total time between events in a transaction.

B.

Sets the maximum length of all events within a transaction.

C.

Sets the maximum total time between the earliest and latest events in a transaction.

D.

Sets the maximum length that any single event can reach to be included in the transaction.

Questions 36

When you mouse over and click to add a search term this (thesE. Boolean operator(s) is(arE. not implied. (Select all that apply).

Options:
A.

OR

B.

( )

C.

AND

D.

NOT

Questions 37

__________ datasets can be added to root dataset to narrow down the search

Options:
A.

parent

B.

extracted

C.

event

D.

child

Questions 38

A data model can consist of what three types of datasets?

Options:
A.

Pivot, searches, and events.

B.

Pivot, events, and transactions.

C.

Searches, transactions, and pivot.

D.

Events, searches, and transactions.

Questions 39

What do events in a transaction have In common?

Options:
A.

All events In a transaction must have the same timestamp.

B.

All events in a transaction must have the same sourcetype.

C.

All events in a transaction must have the exact same set of fields.

D.

All events in a transaction must be related by one or more fields.

Questions 40

This function of the stats command allows you to identify the number of values a field has.

Options:
A.

max

B.

distinct_count

C.

fields

D.

count