Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 8

Questions 71

How could the following syntax for the chart command be rewritten to remove the OTHER category? (select all that apply)

SPLK-1002 Question 71

Options:
A.

| chart count over CurrentStanding by Action useother=f

B.

| chart count over CurrentStanding by Action usenull-f useother-t

C.

| chart count over CurrentStanding by Action limit=10 useother=f

D.

| chart count over CurrentStanding by Action limit-10

Splunk SPLK-1002 Premium Access
Questions 72

Which of the following objects can a calculated field use as a source?

Options:
A.

An alias of a field.

B.

A field added by an automatic lookup.

C.

The tag field.

D.

The eventtype field.

Questions 73

The Field Extractor (FX) is used to extract a custom field. A report can be created using this custom field. The created report can then be shared with other people in the organization. If another person in the organization runs the shared report and no results are returned, why might this be? (select all that apply)

Options:
A.

Fast mode is enabled.

B.

The dashboard is private.

C.

The extraction is private-

D.

The person in the organization running the report does not have access to the index.

Questions 74

When multiple event types with different color values are assigned to the same event, what determines the color displayed for the events?

Options:
A.

Rank

B.

Weight

C.

Priority

D.

Precedence

Questions 75

Which group of users would most likely use pivots?

Options:
A.

Users

B.

Architects

C.

Administrators

D.

Knowledge Managers

Questions 76

Given the macro definition below, what should be entered into the Name and Arguments fileds to correctly configured the macro?

SPLK-1002 Question 76

Options:
A.

The macro name is sessiontracker and the arguments are action, JESSIONID.

B.

The macro name is sessiontracker(2) and the arguments are action, JESSIONID.

C.

The macro name is sessiontracker and the arguments are $action$, $JESSIONID$.

D.

The macro name is sessiontracker(2) and the Arguments are $action$, $JESSIONID$.

Questions 77

Which of the following statements about event types is true? (select all that apply)

Options:
A.

Event types can be tagged.

B.

Event types must include a time range,

C.

Event types categorize events based on a search.

D.

Event types can be a useful method for capturing and sharing knowledge.

Questions 78

What does the fillnull command replace null values with, it the value argument is not specified?

Options:
A.

0

B.

N/A

C.

NaN

D.

NULL

Questions 79

Which of the following file formats can be extracted using a delimiter field extraction?

Options:
A.

CSV

B.

PDF

C.

XML

D.

JSON

Questions 80

Which of the following knowledge objects represents the output of an eval expression?

Options:
A.

Eval fields

B.

Calculated fields

C.

Field extractions

D.

Calculated lookups