Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 6

Questions 51

Which of the following is true about a datamodel that has been accelerated?

Options:
A.

They can be used with Pivot, the | tstats command, or the | datamodel command.

B.

They can still be used in the Pivot tool but only with the accelerate_pivot capability.

C.

They can no longer be used in the Pivot tool.

D.

They can be used with the |tstats command, but will only return that data which has been accelerated.

Splunk SPLK-1002 Premium Access
Questions 52

Which of these search strings is NOT valid:

Options:
A.

index=web status=50* | chart count over host, status

B.

index=web status=50* | chart count over host by status

C.

index=web status=50* | chart count by host, status

Questions 53

Which of the following is a feature of the Pivot tool?

Options:
A.

Creates lookups without using SPL.

B.

Data Models are not required.

C.

Creates reports without using SPL

D.

Datasets are not required.

Questions 54

__________ datasets can be added to root dataset to narrow down the search

Options:
A.

parent

B.

extracted

C.

event

D.

child

Questions 55

Which of the following search control will not re-rerun the search? (Select all that apply.)

Options:
A.

zoom out

B.

selecting a bar on the timeline

C.

deselect

D.

selecting a range of bars on the timelines

Questions 56

The eval command 'if' function requires the following three arguments (in order):

Options:
A.

Boolean expression, result if true, result if false

B.

Result if true, result if false, boolean expression

C.

Result if false, result if true, boolean expression

D.

Boolean expression, result if false, result if true

Questions 57

When used with the timechart command, which value of the limit argument returns all values?

Options:
A.

limit=*

B.

limit=all

C.

limit=none

D.

limit=0

Questions 58

When would transaction be used instead of stats?

Options:
A.

To group events based on a single field value.

B.

To see results of a calculation.

C.

To have a faster and more efficient search.

D.

To group events based on start/end values.

Questions 59

Which workflow action type performs a secondary search?

Options:
A.

POST

B.

Drilldown

C.

GET

D.

Search

Questions 60

A report scheduled to run every 15 mins. but takes 17 mins. to complete is in danger of being_____.

Options:
A.

skipped or deferred

B.

automatically accelerated

C.

deleted

D.

all of the above