Which of the following is NOT a stats function:
which of the following are valid options with the chart command
Which of the following transforming commands can be used with transactions?
The macro weekly_sales (2) contains the search string:
index=games | eval ProductSales = $Price$ * $AmountSold$
Which of the following will return results?
Which search retrieves events with the event type web_errors?
Which of the following examples would use a POST workflow action?
What is the Splunk Common Information Model (CIM)?
Consider the following search:
index=web sourcetype=access_combined
The log shows several events that share the same JSESSIONID value (SD470K92802F117). View the events as a group.
From the following list, which search groups events by JSESSIONID?
Which workflow uses field values to perform a secondary search?
Which workflow action method can be used the action type is set to link?
The fields sidebar does not show________. (Select all that apply.)
Which field will be used to populate the field if the productName and product:d fields have values for a given event?
| eval productINFO=coalesco(productName,productid)
Which of the following statements are true for this search? (Select all that apply.) SEARCH: sourcetype=access* |fields action productld status
When used with the timechart command, which value of the limit argument returns all values?
Which of the following statements describes the use of the Filed Extractor (FX)?
When should the regular expression mode of Field Extractor (FX) be used? (select all that apply)
This function of the stats command allows you to identify the number of values a field has.
What approach is recommended when using the Splunk Common Information Model (CIM) add-on to normalize data?
When extracting fields, we may choose to use our own regular expressions
Information needed to create a GET workflow action includes which of the following? (select all that apply.)
How many ways are there to access the Field Extractor Utility?
When using a field value variable with a Workflow Action, which punctuation mark will escape the data
This function of the stats command allows you to return the sample standard deviation of a field.
What will you learn from the results of the following search?
sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)
Which of the following statements best describes a macro?
A data model can consist of what three types of datasets?
Why are tags useful in Splunk?
Which of the following statements describes an event type?
Select this in the fields sidebar to automatically pipe you search results to the rare command
Where are the results of eval commands stored?
The gauge command:
If there are fields in the data with values that are " " or empty but not null, which of the following would add a value?
A report scheduled to run every 15 mins. but takes 17 mins. to complete is in danger of being_____.
Which of the following statements about calculated fields in Splunk is true?
Using the Field Extractor (FX) tool, a value is highlighted to extract and give a name to a new field. Splunk has not successfully extracted that value from all appropriate events. What steps can be taken so Splunk successfully extracts the value from all appropriate events? (select all that apply)
Which of the following about reports is/are true?
In the Field Extractor, when would the regular expression method be used?
Which of the following knowledge objects can reference field aliases?
Which of the following is a feature of the Pivot tool?
Which of the following eval command function is valid?
Which of the following statements about tags is true?
Which delimiters can the Field Extractor (FX) detect? (select all that apply)
Which are valid ways to create an event type? (select all that apply)
Which of the following statements describe the search below? (select all that apply)
Index=main I transaction clientip host maxspan=30s maxpause=5s
Data model fields can be added using the Auto-Extracted method. Which of the following statements describe Auto-Extracted fields? (select all that apply)
Which of the following Statements about macros is true? (select all that apply)
Which of the following searches show a valid use of macro? (Select all that apply)
Which of the following describes the Splunk Common Information Model (CIM) add-on?
The Field Extractor (FX) is used to extract a custom field. A report can be created using this custom field. The created report can then be shared with other people in the organization. If another person in the organization runs the shared report and no results are returned, why might this be? (select all that apply)
A calculated field maybe based on which of the following?
Which of the following is the correct way to use the data model command to search field in the data model within the web dataset?
Which of the following statements about data models and pivot are true? (select all that apply)
Which one of the following statements about the search command is true?
Which of the following statements describes POST workflow actions?
Which of the following statements describes field aliases?
When using the Field Extractor (FX), which of the following delimiters will work? (select all that apply)
When creating a Search workflow action, which field is required?
Which of the following statements describe calculated fields? (select all that apply)
After manually editing; a regular expression (regex), which of the following statements is true?
Which of the following statements is true, especially in large environments?
Which of the following workflow actions can be executed from search results? (select all that apply)
Given the macro definition below, what should be entered into the Name and Arguments fileds to correctly configured the macro?
How does a user display a chart in stack mode?
In what order arc the following knowledge objects/configurations applied?
What does the fillnull command replace null values with, it the value argument is not specified?
When multiple event types with different color values are assigned to the same event, what determines the color displayed for the events?
Which of the following are required to create a POST workflow action?
When using timechart, how many fields can be listed after a by clause?
What is the relationship between data models and pivots?
Which of the following searches will return events contains a tag name Privileged?
Which of the following actions can the eval command perform?
What is the correct syntax to search for a tag associated with a value on a specific fields?
Which of the following statements describes this search?
sourcetype=access_combined I transaction JSESSIONID | timechart avg (duration)
Which of the following statements describe the Common Information Model (CIM)? (select all that apply)
Calculated fields can be based on which of the following?
Data model are composed of one or more of which of the following datasets? (select all that apply.)
What does the Splunk Common Information Model (CIM) add-on include? (select all that apply)