Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1002 Practice Exam with Questions & Answers | Set: 9

Questions 81

Which of the following statements describe the Common Information Model (CIM)? (select all that apply)

Options:
A.

CIM is a methodology for normalizing data.

B.

CIM can correlate data from different sources.

C.

The Knowledge Manager uses the CIM to create knowledge objects.

D.

CIM is an app that can coexist with other apps on a single Splunk deployment.

Splunk SPLK-1002 Premium Access
Questions 82

These kinds of charts represent a series in a single bar with multiple sections

Options:
A.

Multi-Series

B.

Split-Series

C.

Omit nulls

D.

Stacked

Questions 83

How many ways are there to access the Field Extractor Utility?

Options:
A.

3

B.

4

C.

1

D.

5

Questions 84

Using the export function, you can export search results as __________.( Select all that apply)

Options:
A.

Xml

B.

Json

C.

Html

D.

A php file

Questions 85

Why would the following search produce multiple transactions instead of one?

SPLK-1002 Question 85

Options:
A.

The maxspan option is not included.

B.

The transaction command has a limit of 1000 events per transaction.

C.

The transaction and commands cannot be used together.

D.

The stats list () function is used.

Questions 86

Which of the following statements describe calculated fields? (select all that apply)

Options:
A.

Calculated fields can be used in the search bar.

B.

Calculated fields can be based on an extracted field.

C.

Calculated fields can only be applied to host and sourcetype.

D.

Calculated fields are shortcuts for performing calculations using the eval command.

Questions 87

What does the fillnull command do in this search?

index=main sourcetype=http:log | fillnull value="Unknown"

Options:
A.

Set the values of the field to null when it is "Unknown".

B.

Set all fields that are null to "Unknown".

C.

Set the values of the field to "Unknown" if it is null.

D.

Set all fields with the value of "Unknown" to null.

Questions 88

Which method in the Field Extractor would extract the port number from the following event? |

10/20/2022 - 125.24.20.1 ++++ port 54 - user: admin <web error>

Options:
A.

Delimiter

B.

rex command

C.

The Field Extractor tool cannot extract regular expressions.

D.

Regular expression

Questions 89

The eval command 'if' function requires the following three arguments (in order):

Options:
A.

Boolean expression, result if true, result if false

B.

Result if true, result if false, boolean expression

C.

Result if false, result if true, boolean expression

D.

Boolean expression, result if false, result if true

Questions 90

Which workflow uses field values to perform a secondary search?

Options:
A.

POST

B.

Action

C.

Search

D.

Sub-Search