Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 5

Questions 41

Which of the following describes the Splunk Common Information Model (CIM) add-on?

Options:
A.

The CIM add-on uses machine learning to normalize data.

B.

The CIM add-on contains dashboards that show how to map data.

C.

The CIM add-on contains data models to help you normalize data.

D.

The CIM add-on is automatically installed in a Splunk environment.

Splunk SPLK-1002 Premium Access
Questions 42

Which of the following is true about the Splunk Common Information Model (CIM)?

Options:
A.

The data models included in the CIM are configured with data model acceleration turned off.

B.

The CIM contains 28 pre-configured datasets.

C.

The CIM is an app that needs to run on the indexer.

D.

The data models included in the CIM are configured with data model acceleration turned on.

Questions 43

Consider the following search:

index=web sourcetype=access_combined

The log shows several events that share the same JSESSIONID value (SD470K92802F117). View the events as a group.

From the following list, which search groups events by JSESSIONID?

Options:
A.

index=web sourcetype=access_combined | highlight JSESSIONID | search SD470K92802F117

B.

index=web sourcetype=access_combined | transaction JSESSIONID | search SD470K92802F117

C.

index=web sourcetype=access_combined SD470K92802F117 | table JSESSIONID

D.

index=web sourcetype=access_combined JSESSIONID

Questions 44

When using a field value variable with a Workflow Action, which punctuation mark will escape the data

Options:
A.

*

B.

!

C.

^

D.

#

Questions 45

The stats command will create a _____________ by default.

Options:
A.

Table

B.

Report

C.

Pie chart

Questions 46

What is a limitation of searches generated by workflow actions?

Options:
A.

Searches generated by workflow action cannot use macros.

B.

Searches generated by workflow actions must be less than 256 characters long.

C.

Searches generated by workflow action must run in the same app as the workflow action.

D.

Searches generated by workflow action run with the same permissions as the user running them.

Questions 47

When defining a macro, what are the required elements?

Options:
A.

Name and arguments.

B.

Name and a validation error message.

C.

Name and definition.

D.

Definition and arguments.

Questions 48

Which knowledge Object does the Splunk Common Information Model (CIM) use to normalize data. in addition to field aliases, event types, and tags?

Options:
A.

Macros

B.

Lookups

C.

Workflow actions

D.

Field extractions

Questions 49

Which of the following statements is true about the root dataset of a data model?

Options:
A.

It can contain transforming commands as long as it is a root search dataset.

B.

It will automatically contain knowledge objects associated with the base search.

C.

It must contain the transaction command if it is a root transaction dataset.

D.

It can only contain a base search with no transforming commands.

Questions 50

Select this in the fields sidebar to automatically pipe you search results to the rare command

Options:
A.

events with this field

B.

rare values

C.

top values by time

D.

top values