Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Splunk SPLK-1004 Dumps

Page: 1 / 5
Total 70 questions

Splunk Core Certified Advanced Power User Questions and Answers

Question 1

What does the query | makeresults generate?

Options:

A.

A timestamp

B.

A results field

C.

An error message

D.

The results of the previously run search.

Question 2

which function of the stats command creates a multivalue entry?

Options:

A.

mvcombine

B.

eval

C.

makemv

D.

list

Question 3

Which of the following is not a common default time field?

Options:

A.

date_zone

B.

date minute

C.

date_year

D.

date_day

Question 4

How can the inspect button be disabled on a dashboard panel?

Options:

A.

Set inspect.link.disabled to 1

B.

Set link.inspect .visible to 0

C.

Set link.inspectSearch.visible too

D.

Set link.search.disabled to 1

Question 5

What XML element is used to pass multiple fields into another dashboard using a dynamic drilldown?

Options:

A.

B.

C.

D.

Question 6

Why use the tstats command?

Options:

A.

As an alternative to the summary command.

B.

To generate statistics on indexed fields.

C.

To generate an accelerated datamodel.

D.

To generate statistics on search-time fields.

Question 7

Which commands can run on both search heads and indexers?

Options:

A.

Transforming commands

B.

Centralized streaming commands

C.

Dataset processing commands

D.

Distributable streaming commands

Question 8

Which of the following are potential string results returned by the type of function?

Options:

A.

True, False, Unknown

B.

Number, Siring, Bool

C.

Number, String, Null

D.

Field, Value, Lookup

Question 9

What default Splunk role can use the Log Event alert action?

Options:

A.

Power

B.

User

C.

can_delete

D.

Admin

Question 10

Which of the following statements is accurate regarding the append command?

Options:

A.

It is used with a subsearch and only accesses real-lime searches.

B.

It is used with a subsearch and oily accesses historical data.

C.

It cannot be used with a subsearch and only accesses historical data.

D.

It cannot be used with a subsearch and only accesses real-time searches.

Question 11

Which of the following fields are provided by the fieldsummary command? (select all that apply)

Options:

A.

count

B.

stdev

C.

mean

D.

dc

Question 12

What is a performance improvement technique unique to dashboards?

Options:

A.

Using stats instead of transaction

B.

Using global searches

C.

Using report acceleration

D.

Using datamodel acceleration

Question 13

Which of the following Is valid syntax for the split function?

Options:

A.

...| eval split phoneNUmber by "_" as areaCodes.

B.

...| eval areaCodes = split (phonNumber, "_"

C.

...| eval phoneNumber split("-", 3, areaCodes)

D.

...| eval split (phone-Number, "_", areaCodes)

Question 14

How can a lookup be referenced in an alert?

Options:

A.

Use the lookup dropdown in the alert configuration window.

B.

Follow a lookup with an alert command in the search bar.

C.

Run a search that uses a lookup and save as an alert.

D.

Upload a lookup file directly to the alert.

Question 15

What are the four types of event actions?

Options:

A.

stats, target, set, and unset

B.

stats, target, change, and clear

C.

eval, link, change, and clear

D.

eval, link, set, and unset

Question 16

When using the bin command, which argument sets the bin size?

Options:

A.

mazDataSizeMB

B.

max

C.

volume

D.

span

Question 17

What file types does Splunk use to define geospatial lookups?

Options:

A.

GPX or GML files

B.

TXT files

C.

KMZ or KML files

D.

CSV files

Question 18

Why is the transaction command slow in large splunk deployments?

Options:

A.

It forces the search to run in fast mode.

B.

transaction or runs on each Indexer in parallel.

C.

It forces all event data to be returned to the search head.

D.

transaction runs a hidden eval to format fields.

Question 19

Repeating JSON data structures within one event will be extracted as what type of fields?

Options:

A.

Single value

B.

Lexicographical

C.

Multivalue

D.

Mvindex

Question 20

What is an example of the simple XML syntax for a base search and its post-srooess search?

Options:

A.

,

B.

,

C.

,

D.

,

Question 21

Which command processes a template for a set of related fields?

Options:

A.

bin

B.

xyseries

C.

foreach

D.

untable

Page: 1 / 5
Total 70 questions