Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 9

Questions 81

Which of the following is NOT a stats function:

Options:
A.

sum

B.

addtotals

C.

count

D.

avg

Splunk SPLK-1002 Premium Access
Questions 82

Two separate results tables are being combined using the |join command. The outer table has the following values:

Refer to following Tables

SPLK-1002 Question 82

The line of SPL used to join the tables is: | join employeeNumber type=outer

How many rows are returned in the new table?

Options:
A.

Zero

B.

Five

C.

Eight

D.

Three

Questions 83

Based on the macro definition shown below, what is the correct way to execute the macro in a search string?

SPLK-1002 Question 83

Options:
A.

Convert_sales (euro, €, 79)”

B.

Convert_sales (euro, €, .79)

C.

Convert_sales ($euro,$€$,s79$

D.

Convert_sales ($euro, $€$,S,79$)

Questions 84

which of the following commands are used when creating visualizations(select all that apply.)

Options:
A.

Geom

B.

Choropleth

C.

Geostats

D.

iplocation

Questions 85

Consider the following search:

Index=web sourcetype=access_combined

The log shows several events that share the same JSESSIONID value (SD404K289O2F151). View the events as a group. From the following list, which search groups events by JSESSIONID?

Options:
A.

index=web sourcetype=access_combined SD404K289O2F151 I table JSESSIONID

B.

index=web sourcetype=access_combined JSESSIONID

C.

index=web sourcetype=access_combined I highlight JSESSIONID I search SD404K289O2F151

D.

index-web sourcetype=access_combined I transaction JSESSIONID I search SD404K289O2F151

Questions 86

Data model fields can be added using the Auto-Extracted method. Which of the following statements describe Auto-Extracted fields? (select all that apply)

Options:
A.

Auto-Extracted fields can be hidden in Pivot.

B.

Auto-Extracted fields can have their data type changed.

C.

Auto-Extracted fields can be given a friendly name for use in Pivot.

D.

Auto-Extracted fields can be added if they already exist in the dataset with constraints.

Questions 87

Splunk alerts can be based on search that run______. (Select all that apply.)

Options:
A.

in real-time

B.

on a regular schedule

C.

and have no matching events

Questions 88

Which of the following is included with the Splunk Common Information Model (CIM) Add-on?

Options:
A.

Sourcetype definitions from the most popular technology vendors.

B.

A set of pre-configured data models.

C.

Scripted inputs to pre-align data with the CIM.

D.

Dashboards to validate data quality.