Topic 1 : Main Questions
Which of the following searches show a valid use of macro? (Select all that apply)
A.
Option A
B.
Option B
C.
Option C
D.
Option D
Option A
Option C
Which of the following can be used with the eval command tostring function (select all that apply)
A.
‘’hex’’
B.
‘’commas’’
C.
‘’Decimal’’
D.
‘’duration’’
‘’hex’’
‘’commas’’
‘’duration’’
Based on the macro definition shown below, what is the correct way to execute the macro in search string?
A.
Convert_sales (euro, €, 79)”
B.
Convert_sales (euro, €, .79)
C.
Convert_sales ($euro,$€$,s79$
D.
Convert_sales ($euro, $€$,S,79$)
Convert_sales (euro, €, .79)
What does the fillnull command replace null values with, it the value argument is not specified?
A.
0
B.
N/A
C.
NaN
D.
NULL
0
What does the Splunk Common Information Model (CIM) add-on include? (select all that apply)
A.
Custom visualizations
Pre-configured data models
Fields and event category tags
Automatic data model acceleration
B.
Pre-configured data models
C.
Fields and event category tags
D.
Automatic data model acceleration
Custom visualizations
Pre-configured data models
Fields and event category tags
Automatic data model acceleration
Fields and event category tags
When using the Field Extractor (FX), which of the following delimiters will work? (select all that apply)
A.
Tabs
B.
Pipes
C.
Colons
D.
Spaces
Tabs
Pipes
Spaces
Calculated fields can be based on which of the following?
A.
Tags
B.
Extracted fields
C.
Output fields for a lookup
D.
Fields generated from a search string
Extracted fields
Which of the following statements describes the command below (select all that apply)
sourcetype-access_combined | transaction JSESSIONID
A.
An additional filed named maxspan is created.
B.
An additional Held named duration is created.
C.
An additional field named eventcount is created.
D.
Events with the same JSESSIONID will be grouped together into a single event.
An additional Held named duration is created.
An additional field named eventcount is created.
Which of the following describes the Splunk Common Information Model (CIM) add-on?
A.
The CIM add-on uses machine learning to normalize data.
B.
The CIM add-on contains dashboards that show how to map data.
C.
The CIM add-on contains data models to help you normalize data.
D.
The CIM add-on is automatically installed in a Splunk environment.
The CIM add-on contains data models to help you normalize data.
What does the transaction command do?
A.
Groups a set of transactions based on time.
B.
Creates a single event from a group of events.
C.
Separates two events based on one or more values.
D.
Returns the number of credit card transactions found in the event logs.
Creates a single event from a group of events.
Page 4 out of 13 Pages |
Previous |