Which of the following expressions could be used to create a calculated field called gigabytes?
A. eval sc_bytes(1024/1024)
B. | eval negabytes=sc_bytes(1024/1024)
C. megabytes=sc_bytes(1024/1024)
D. sc_bytas(1024/1024)
A user runs the following search:
index--X sourcetype=Y I chart count (domain) as count, sum (price) as sum by product, action usenull=f useother--f
Which of the following table headers match the order this command creates?
A. The chart command does not allow for multiple statistical functions.
B. Product, sum: addtocart, sum: remove, sum: purchase, count: addtocart, count: remove, count: purchase
C. Product, count: addtocart, count: remove, count: purchase, sum: addtocart, sum: remove, sum: purchase
D. Count: product, sum: product, count: action, sum: action
When using the transaction command, what does the argument maxspan do?
A. Sets the maximum total time between events in a transaction.
B. Sets the maximum length of all events within a transaction.
C. Sets the maximum total time between the earliest and latest events in a transaction.
D. Sets the maximum length that any single event can reach to be included in the transaction.
The macro weekly_sales (2) contains the search string:
index--games I eval Product Sales = $price$ $AmountS01d$
Which of the following will return results?
A. `weekly_sales(3.99, 10) '
B. `weekly_sales($3.99$, $10$)
C. 'weekly_sales (3.99, 10)
D. `weekly_sales(3)
The transaction command allows you to __________ events across multiple sources
A. duplicate
B. correlate
C. persist
D. tag
In the Field Extractor, when would the regular expression method be used?
A. When events contain JSON data.
B. When events contain comma-separated data.
C. When events contain unstructured data.
D. When events contain table-based data.
Which of the following is true about the Splunk Common Information Model (CIM)?
A. The data models included in the CIM are configured with data model acceleration turned off.
B. The CIM contains 28 pre-configured datasets.
C. The CIM is an app that needs to run on the indexer.
D. The data models included in the CIM are configured with data model acceleration turned on.
Which field extraction method should be selected for comma-separated data?
A. Regular expression
B. Delimiters
C. eval expression
D. table extraction
There are several ways to access the field extractor. Which option automatically identifies data type, source type, and sample event?
A. Event Actions > Extract Fields
B. Fields sidebar > Extract New Field
C. Settings > Field Extractions > New Field Extraction D. Settings > Field Extractions > Open Field Extraction
Which of the following statements about tags is true?
A. Tags are case insensitive.
B. Tags can make your data more understandable.
C. Tags are created at index time.
D. Tags are searched by using the syntax tag ::
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Splunk exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SPLK-1002 exam preparations and Splunk certification application, do not hesitate to visit our Vcedump.com to find your solutions here.