A calculated field may be based on which of the following?
A. Fields generated within a search string
B. Lookup tables
C. Regular expressions
D. Extracted fields
Which of the following knowledge objects can reference field aliases?
A. Calculated fields, lookups, event types, and tags.
B. Calculated fields and tags only.
C. Calculated fields and event types only.
D. Calculated fields, lookups, event types, and extracted fields.
Which of these is NOT a field that is automatically created with the transaction command?
A. maxcount
B. duration
C. eventcount
Which of these search strings is NOT valid:
A. index=web status=50* | chart count over host, status
B. index=web status=50* | chart count over host by status
C. index=web status=50* | chart count by host, status
Which is not a comparison operator in Splunk
A. <=
B. =
C. !=
D. >
E. ?=
Calculated fields can be based on which of the following?
A. Tags
B. Extracted fields
C. Output fields for a lookup
D. Fields generated from a search string
This function of the stats command allows you to identify the number of values a field has.
A. max
B. distinct_count
C. fields
D. count
When using | timechart by host, which field is represented in the x-axis?
A. date
B. host
C. time
D. _time
The timechart command is an example of which of the following command types?
A. Orchestrating
B. Transforming
C. Statistical
D. Generating
Which of the following is NOT a stats function:
A. sum
B. addtotals
C. count
D. avg
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Splunk exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SPLK-1002 exam preparations and Splunk certification application, do not hesitate to visit our Vcedump.com to find your solutions here.