Go Back on SPLK-1002 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

SPLK-1002 Practice Test


Page 9 out of 26 Pages

Topic 1 : Main Questions

Which of the following workflow actions can be executed from search results? (select all that apply)


A.

GET


B.

POST


C.

LOOKUP


D.

Search





A.
  

GET



B.
  

POST



D.
  

Search



Which of the following statements describe calculated fields? (select all that apply)


A.

Calculated fields can be used in the search bar.


B.

Calculated fields can be based on an extracted field.


C.

Calculated fields can only be applied to host and sourcetype.


D.

Calculated fields are shortcuts for performing calculations using the eval command.





B.
  

Calculated fields can be based on an extracted field.



D.
  

Calculated fields are shortcuts for performing calculations using the eval command.



Which of the following statements describe the search below? (select all that apply)
Index=main I transaction clientip host maxspan=30s maxpause=5s


A.

Events in the transaction occurred within 5 seconds.


B.

It groups events that share the same clientip and host.


C.

The first and last events are no more than 5 seconds apart.


D.

The first and last events are no more than 30 seconds apart.





B.
  

It groups events that share the same clientip and host.



When creating a Search workflow action, which field is required?


A.

Search string


B.

Data model name


C.

Permission setting


D.

An eval statement





C.
  

Permission setting



Data model are composed of one or more of which of the fo-owing datasets? (select all that apply.)


A.

Events datasets


B.

Search datasets


C.

Transaction datasets


D.

Any child of event, transaction, and search datasets





A.
  

Events datasets



B.
  

Search datasets



C.
  

Transaction datasets




Page 9 out of 26 Pages
Previous