Go Back on SPLK-1002 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

SPLK-1002 Practice Test


Page 5 out of 26 Pages

Topic 1 : Main Questions

Which of the following statements is true, especially in largo environments?


A.

Use the scats command when you next to group events by two or more fields.


B.

The scats command is faster and more efficient than the transaction command


C.

The transaction command is faster and more efficient than the stats command.


D.

Use the transaction command when you want to see the results of a calculation.





C.
  

The transaction command is faster and more efficient than the stats command.



Which of the following statements describe the Common Information Model (QM)? (select all that apply)


A.

CIM is a methodology for normalizing data.


B.

CIM can correlate data from different sources.


C.

The Knowledge Manager uses the CIM to create knowledge objects.


D.

CIM is ^n app that can coexist with other apps on a single Splunk deployment.





C.
  

The Knowledge Manager uses the CIM to create knowledge objects.



In which of the following scenarios is an event type more effective than a saved search?


A.

When a search should always include the same time range.


B.

When a search needs to be added to other users' dashboards.


C.

When the search string needs to be used in future searches.


D.

When formatting needs to be included with the search string.





D.
  

When formatting needs to be included with the search string.



Given the macro definition below, what should be entered into the Name and Arguments fileds to correctly configured the macro



A.

The macro name is sessiontracker and the argument are action, JESSION.


B.

The macro name is sessiontracker (2) and the action JESSIONID


C.

The macro name is sessiontracker and the argument are sectional ,$ JESSIONIDS.


D.

The macro name is sessiontracker (2) and the argument are $action ,$JESSIONIDS





B.
  

The macro name is sessiontracker (2) and the action JESSIONID



Which of the following is the correct way to use the data model command to search field in the data model within the web dataset?


A.

| datamodel web search | filed web *


B.

| Search datamodel web web | filed web*


C.

| datamodel web web field | search web*


D.

Datamodel=web | search web | filed web*





A.
  

| datamodel web search | filed web *




Page 5 out of 26 Pages
Previous