Weekend Sale Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Splunk SPLK-1004 Questions Answers

Page: 4 / 5
Total 70 questions

Splunk Core Certified Advanced Power User Questions and Answers

Question 13

Which of the following Is valid syntax for the split function?

Options:

A.

...| eval split phoneNUmber by "_" as areaCodes.

B.

...| eval areaCodes = split (phonNumber, "_"

C.

...| eval phoneNumber split("-", 3, areaCodes)

D.

...| eval split (phone-Number, "_", areaCodes)

Question 14

How can a lookup be referenced in an alert?

Options:

A.

Use the lookup dropdown in the alert configuration window.

B.

Follow a lookup with an alert command in the search bar.

C.

Run a search that uses a lookup and save as an alert.

D.

Upload a lookup file directly to the alert.

Question 15

What are the four types of event actions?

Options:

A.

stats, target, set, and unset

B.

stats, target, change, and clear

C.

eval, link, change, and clear

D.

eval, link, set, and unset

Question 16

When using the bin command, which argument sets the bin size?

Options:

A.

mazDataSizeMB

B.

max

C.

volume

D.

span

Page: 4 / 5
Total 70 questions