Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 6

Questions 51

What are the two parts of a root event dataset?

Options:
A.

Fields and variables.

B.

Fields and attributes.

C.

Constraints and fields.

D.

Constraints and lookups.

Splunk SPLK-1002 Premium Access
Questions 52

Clicking a SEGMENT on a chart, ________.

Options:
A.

drills down for that value

B.

highlights the field value across the chart

C.

adds the highlighted value to the search criteria

Questions 53

Which of the following statements describes this search?

sourcetype=access_combined I transaction JSESSIONID | timechart avg (duration)

Options:
A.

This is a valid search and will display a timechart of the average duration, of each transaction event.

B.

This is a valid search and will display a stats table showing the maximum pause among transactions.

C.

No results will be returned because the transaction command must include the startswith and endswith options.

D.

No results will be returned because the transaction command must be the last command used in the search pipeline.

Questions 54

This function of the stats command allows you to return the middle-most value of field X.

Options:
A.

Median(X)

B.

Eval by X

C.

Fields(X)

D.

Values(X)

Questions 55

When performing a regex field extraction with the Field Extractor (FX), a data type must be chosen before a sample event can be selected. Which of the following data types are supported?

Options:
A.

index or source

B.

sourcetype or host

C.

index or sourcetype

D.

sourcetype or source

Questions 56

What other syntax will produce exactly the same results as | chart count over vendor_action by user?

Options:
A.

| chart count by vendor_action, user

B.

| chart count over vendor_action, user

C.

| chart count by vendor_action over user

D.

| chart count over user by vendor_action

Questions 57

Which of the following searches will return events containing a tag named Privileged?

Options:
A.

tag=Priv

B.

tag=Priv*

C.

tag=priv*

D.

tag=privileged

Questions 58

How are event types different from saved reports?

Options:
A.

Event types cannot be used to organize data into categories.

B.

Event types include formatting of the search results.

C.

Event types can be shared with Splunk users and added to dashboards.

D.

Event types do not include a time range.

Questions 59

Data model fields can be added using the Auto-Extracted method. Which of the following statements describe Auto-Extracted fields? (select all that apply)

Options:
A.

Auto-Extracted fields can be hidden in Pivot.

B.

Auto-Extracted fields can have their data type changed.

C.

Auto-Extracted fields can be given a friendly name for use in Pivot.

D.

Auto-Extracted fields can be added if they already exist in the dataset with constraints.

Questions 60

What do events in a transaction have In common?

Options:
A.

All events In a transaction must have the same timestamp.

B.

All events in a transaction must have the same sourcetype.

C.

All events in a transaction must have the exact same set of fields.

D.

All events in a transaction must be related by one or more fields.