SPLK-1002 Practice Test Questions

272 Questions


Topic 2: Questions Set 2

Which of the following is true about Pivot?


A. Users can save reports from Pivot.


B. Users cannot share visualizations created with Pivot.


C. Users must use SPL to find events in a Pivot.


D. Users cannot create visualizations with Pivot.





By default search results are not returned in ________ order.


A. Chronological


B. Reverser chronological


C. ASCIE


D. Alphabetical





Which of the following is a function of the Splunk Common Information Model (CIM)?


A. Normalizing data across a Splunk deployment.


B. Providing templates for reports and dashboards.


C. Algorithmically shifting events to other indexes.


D. Reingesting previously indexed data with new field names.





When using transaction, what is the default maximum span between events?


A. Unlimited


B. 1h


C. 1m


D. 1d





What is the correct format for naming a macro with multiple arguments?


A. monthly_sales(argument 1, argument 2, argument 3)


B. monthly_sales(3)


C. monthly_sales[3]


D. monthly_sales[argument 1, argument 2, argument 3)





The Splunk Common Information Model (CIM) is a collection of what type of knowledge object?


A. KV Store


B. Lookups


C. Saved searches


D. Data models





What is the correct way to name a macro with two arguments?


A. us_sales2


B. us_sales(1,2)


C. us_sale,2


D. us_sales(2)





Which of the following search control will not re-rerun the search? (Select all that apply.)


A. zoom out


B. selecting a bar on the timeline


C. deselect


D. selecting a range of bars on the timelines





Which of the following statements about tags is true?


A. Tags are case insensitive.


B. Tags can make your data more understandable.


C. Tags are created at index time.


D. Tags are searched by using the syntax tag :: .





Which of the following are valid options to speed up reports? (Select all the apply.)


A. Edit permissions


B. Edit description


C. Edit acceleration


D. Edit schedule





We can use the rename command to _____ (Select all that apply.)


A. Change indexed fields


B. Exclude fields from our search results


C. Extract new fields from our data using regular expressions


D. Give a field a new name at search time





The eval command allows you to do which of the following? (Choose all that apply.)


A. Format values


B. Convert values


C. Perform calculations


D. Use conditional statements






Page 7 out of 23 Pages
Previous