Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Splunk SPLK-1004 Actual Questions

Page: 6 / 9
Total 120 questions

Splunk Core Certified Advanced Power User Exam Questions and Answers

Question 21

Which of the following is a valid event action in Splunk?

Options:

A.

Execute an eval statement.

B.

Edit an event in the raw data.

C.

Execute a stats statement.

D.

Create a new REST API endpoint.

Question 22

A report named "Linux logins" populates a summary index with the search string sourcetype=linux_secure | sitop src_ip user. Which of the following correctly searches against the summary index for this data?

Options:

A.

index=summary sourcetype="linux_secure" | top src_ip user

B.

index=summary search_name="Linux logins" | top src_ip user

C.

index=summary search_name="Linux logins" | stats count by src_ip user

D.

index=summary sourcetype="linux_secure" | stats count by src_ip user

Question 23

What are the four types of event actions?

Options:

A.

stats, target, set, and unset

B.

stats, target, change, and clear

C.

eval, link, change, and clear

D.

eval, link, set, and unset

Question 24

What is the correct hierarchy of XML elements in a dashboard panel?

Options:

A.

B.

C.

D.

Page: 6 / 9
Total 120 questions