SPLK-1002 Exam Questions

Total 128 Questions

Last Updated Exam : 16-Dec-2024

Topic 1 : Main Questions

When multiple event types with different color values are assigned to the same event, what determines the color displayed for the events?


A.

Rank


B.

Weight


C.

Priority


D.

Precedence





C.
  

Priority



A user wants to convert field values to string and also to sort on those value. Which command should be used first, the eval or the sort?


A.

It doesn't matter whether eval or sort is used first.


B.

Convert the numeric to a string with eval first, then sort.


C.

Use sort first, then convert the numeric to a string with eval.


D.

You cannot use the sort command and the eval command on the same field.





B.
  

Convert the numeric to a string with eval first, then sort.



Which delimiters can the Field Extractor (FX) detect? (select all that apply)


A.

Tabs


B.

Pipes


C.

Spaces


D.

Commas





A.
  

Tabs



B.
  

Pipes



C.
  

Spaces



To identify all of the contributing events within a transaction that contains at least one REJECT event, which
syntax is correct?


A.

Index-main | REJECT trans sessionid


B.

Index-main | transaction sessionid | search REJECT


C.

Index=main | transaction sessionid | whose transaction=reject


D.

Index=main | transaction sessionid | where transaction=reject’’





C.
  

Index=main | transaction sessionid | whose transaction=reject



Which group of users would most likely use pivots?


A.

Users


B.

Architects


C.

Administrators


D.

Knowledge Managers





D.
  

Knowledge Managers



When should you use the transaction command instead of the scats command?


A.

When you need to group on multiple values.


B.

When duration is irrelevant in search results. .


C.

When you have over 1000 events in a transaction.


D.

When you need to group based on start and end constraints.





C.
  

When you have over 1000 events in a transaction.



Which of the following statements describe data model acceleration? (select all that apply)


A.

Root events cannot be accelerated.


B.

Accelerated data models cannot be edited.


C.

Private data models cannot be accelerated.


D.

You must have administrative permissions or the accelerate_dacamodel capability to accelerate a data
model.





B.
  

Accelerated data models cannot be edited.



C.
  

Private data models cannot be accelerated.



A space is an implied _____ in a search string.


A.

OR


B.

AND


C.

()


D.

NOT





B.
  

AND



Which of the following knowledge objects represents the output of an oval expression?


A.

Eval fields


B.

Calculated fields


C.

Field extractions


D.

Calculated lookups





C.
  

Field extractions



Which of the following data model are included In the Splunk Common Information Model (CIM) add-on? 
(select all that apply)


A.

Alerts


B.

Email
Database
User permissions


C.

Database


D.

User permissions





A.
  

Alerts



B.
  

Email
Database
User permissions



C.
  

Database




Page 2 out of 13 Pages
Previous