Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Splunk Core Certified Power User SPLK-1002 Splunk Study Notes

Page: 13 / 23
Total 313 questions

Splunk Core Certified Power User Exam Questions and Answers

Question 49

Which of these is NOT a field that is automatically created with the transaction command?

Options:

A.

maxcount

B.

duration

C.

eventcount

Question 50

Which of the following options will define the first event in a transaction?

Options:

A.

startswith

B.

with

C.

startingwith

D.

firstevent

Question 51

Which of the following statements describe calculated fields? (select all that apply)

Options:

A.

Calculated fields can be used in the search bar.

B.

Calculated fields can be based on an extracted field.

C.

Calculated fields can only be applied to host and sourcetype.

D.

Calculated fields are shortcuts for performing calculations using the eval command.

Question 52

Splunk alerts can be based on search that run______. (Select all that apply.)

Options:

A.

in real-time

B.

on a regular schedule

C.

and have no matching events

Page: 13 / 23
Total 313 questions