Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 7

Questions 61

Which of these search strings is NOT valid:

Options:
A.

index=web status=50* | chart count over host, status

B.

index=web status=50* | chart count over host by status

C.

index=web status=50* | chart count by host, status

Splunk SPLK-1002 Premium Access
Questions 62

Which of the following statements describes an event type?

Options:
A.

A log level measurement: info, warn, error.

B.

A knowledge object that is applied before fields are extracted.

C.

A field for categorizing events based on a search string.

D.

Either a log, a metric, or a trace.

Questions 63

When can a pipe follow a macro?

Options:
A.

A pipe may always follow a macro.

B.

The current user must own the macro.

C.

The macro must be defined in the current app.

D.

Only when sharing is set to global for the macro.

Questions 64

A Splunk app is configured to extract domain names in web service logs and specify them as a field named domain.

What workflow action would return an external IP lookup for the field named domain?

Options:
A.

POST

B.

PUT

C.

GET

D.

Search

Questions 65

Which type of visualization shows relationships between discrete values in three dimensions?

Options:
A.

Pie chart

B.

Line chart

C.

Bubble chart

D.

Scatter chart

Questions 66

A user wants to convert numeric field values to strings and also to sort on those values.

Which command should be used first, the eval or the sort?

Options:
A.

It doesn't matter whether eval or sort is used first.

B.

Convert the numeric to a string with eval first, then sort.

C.

Use sort first, then convert the numeric to a string with eval.

D.

You cannot use the sort command and the eval command on the same field.

Questions 67

Which delimiters can the Field Extractor (FX) detect? (select all that apply)

Options:
A.

Tabs

B.

Pipes

C.

Spaces

D.

Commas

Questions 68

Which of the following actions can the eval command perform?

Options:
A.

Remove fields from results.

B.

Create or replace an existing field.

C.

Group transactions by one or more fields.

D.

Save SPL commands to be reused in other searches.

Questions 69

Why are tags useful in Splunk?

Options:
A.

Tags look for less specific data.

B.

Tags visualize data with graphs and charts.

C.

Tags group related data together.

D.

Tags add fields to the raw event data.

Questions 70

What is the Splunk Common Information Model (CIM)?

Options:
A.

The CIM is a prerequisite that any data source must meet to be successfully onboarded into Splunk.

B.

The CIM provides a methodology to normalize data from different sources and source types.

C.

The CIM defines an ecosystem of apps that can be fully supported by Splunk.

D.

The CIM is a data exchange initiative between software vendors.