Set 9
Set 9
Options:
A) tag=alert
B) host::tag::alert
C) tag==alert
D) tag::host=alert
Answer:
D
Question 2
Question Type: MultipleChoice
Which of the following statements describe the Common Information Model (QM)? (select all that apply)
Options:
A) CIM is a methodology for normalizing data.
D) CIM is an app that can coexist with other apps on a single Splunk deployment.
Answer:
A, B, C
Explanation:
https://docs.splunk.com/Documentation/CIM/4.15.0/User/Overview
Question 3
Question Type: MultipleChoice
Which of the following knowledge objects represents the output of an oval expression?
Options:
A) Eval fields
B) Calculated fields
C) Field extractions
D) Calculated lookups
Answer:
B
Explanation:
https://docs.splunk.com/Splexicon:Calculatedfield
Question 4
Question Type: MultipleChoice
Data model are composed of one or more of which of the fo-owing datasets? (select all that apply.)
Options:
A) Events datasets
B) Search datasets
C) Transaction datasets
Answer:
A, B, C
Explanation:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Knowledge/Aboutdatamodels
Question 5
Question Type: MultipleChoice
Which of the following statements describe the search string below?
Options:
A) Events will be returned from dataset named Application_state.
D) No events will be returned because the pipe should occur after the datamodel command
Answer:
C
Question 6
Question Type: MultipleChoice
When using timechart, how many fields can be listed after a by clause? ( Choose Two )
Options:
A) because timechart doesn't support using a by clause.
C) because one field would represent the x-axis and the other would represent the y-axis.
Answer:
B, D
Question 7
Question Type: MultipleChoice
A user wants to convert field values to string and also to sort on those value. Which command should be used first, the eval or the sort?
Options:
A) It doesn't matter whether eval or sort is used first.
B) Convert the numeric to a string with eval first, then sort.
C) Use sort first, then convert the numeric to a string with eval.
D) You cannot use the sort command and the eval command on the same field.
Answer:
B
Question 8
Question Type: MultipleChoice
Options:
A) Remove fields from results.
Question 9
Question Type: MultipleChoice
Options:
A) Use the scats command when you next to group events by two or more fields.
B) The scats command is faster and more efficient than the transaction command
C) The transaction command is faster and more efficient than the stats command.
D) Use the transaction command when you want to see the results of a calculation.
Answer:
C
Question 10
Question Type: MultipleChoice
Options:
A) Creates a table of the total count of users and split by corndogs.
C) Creates a table with the count of all types of corndogs eaten split by user.
D) Creates a table that groups the total number of users by vegetarian corndogs.
Answer:
A
To Get Premium Files for SPLK-1002 Visit
https://www.p2pexams.com/products/splk-1002