Which of the following actions can the eval command perform?
Which of the following statements about event types is true? (select all that apply)
Which of the following searches show a valid use of macro? (Select all that apply)
When using timechart, how many fields can be listed after a by clause?
What are the two parts of a root event dataset?
When performing a regular expression (regex) field extraction using the Field Extractor (FX), what happens when the require option is used?
Calculated fields can be based on which of the following?
Which of the following knowledge objects represents the output of an eval expression?
What do events in a transaction have In common?
Which of the following describes the Splunk Common Information Model (CIM) add-on?
Which of the following data model are included In the Splunk Common Information Model (CIM) add-on? (select all that apply)
Which of the following statements describes POST workflow actions?
Which of the following is the correct way to use the data model command to search field in the data model within the web dataset?
Which of the following file formats can be extracted using a delimiter field extraction?
To identify all of the contributing events within a transaction that contains at least one REJECT event, which syntax is correct?
What does the Splunk Common Information Model (CIM) add-on include? (select all that apply)
Which of the following statements describes field aliases?
Which of the following eval command function is valid?
Which of the following statements describes Search workflow actions?
When should you use the transaction command instead of the scats command?
Which of the following statements about data models and pivot are true? (select all that apply)
When using the Field Extractor (FX), which of the following delimiters will work? (select all that apply)
What is required for a macro to accept three arguments?
Which of the following statements describes macros?
Which group of users would most likely use pivots?
Based on the macro definition shown below, what is the correct way to execute the macro in a search string?
When multiple event types with different color values are assigned to the same event, what determines the color displayed for the events?
Which of the following statements describes the command below (select all that apply)
Sourcetype=access_combined | transaction JSESSIONID
When creating a Search workflow action, which field is required?
Which of the following statements describe calculated fields? (select all that apply)
After manually editing; a regular expression (regex), which of the following statements is true?
What does the fillnull command replace null values with, it the value argument is not specified?
How does a user display a chart in stack mode?
What does the transaction command do?
A calculated field maybe based on which of the following?
Which of the following are required to create a POST workflow action?
Which of the following statements describe the search below? (select all that apply)
Index=main I transaction clientip host maxspan=30s maxpause=5s
Which of the following statements describe GET workflow actions?
Which of the following searches will show the number of categoryld used by each host?
What happens when a user edits the regular expression (regex) field extraction generated in the Field Extractor (FX)?
Consider the following search:
index=web sourcetype=access_combined
The log shows several events that share the same JSESSIONID value (SD470K92802F117). View the events as a group.
From the following list, which search groups events by JSESSIONID?
When using the timechart command, how can a user group the events into buckets based on time?
When creating a data model, which root dataset requires at least one constraint?
Which of the following transforming commands can be used with transactions?
A macro has another macro nested within it, and this inner macro requires an argument. How can the user pass this argument into the SPL?
Which of the following describes this search?
New Search
'third_party_outages(EMEA,-24h)'
Which of the following is a function of the Splunk Common Information Model (CIM)?
Which of the following statements best describes a macro?
How is an event type created from the search window? (select all that apply)
Which workflow action method can be used the action type is set to link?
What information must be included when using the datamodel command?
Which of the following statements describes POST workflow actions?
During the validation step of the Field Extractor workflow:
Select your answer.
Clicking a SEGMENT on a chart, ________.
Tags can reference which of the following knowledge objects?
Which of the following searches would create a graph similar to the one below?
A user wants to create a new field alias for a field that appears in two sourcetypes.
How many field aliases need to be created?
which of the following commands are used when creating visualizations(select all that apply.)
Splunk alerts can be based on search that run______. (Select all that apply.)
The macro weekly_sales (2) contains the search string:
index—games I eval Product Sales = $price$ $AmountS01d$
Which of the following will return results?
When can a pipe follow a macro?
The stats command will create a _____________ by default.
The eval command 'if' function requires the following three arguments (in order):
Which of the following search modes automatically returns all extracted fields in the fields sidebar?
By default search results are not returned in ________ order.
What commands can be used to group events from one or more data sources?
What is a limitation of searches generated by workflow actions?
Which of the following statements about tags is true? (select all that apply.)
When you mouse over and click to add a search term this (thesE. Boolean operator(s) is(arE. not implied. (Select all that apply).
How are event types different from saved reports?
This function of the stats command allows you to return the sample standard deviation of a field.
When would transaction be used instead of stats?
In which Settings section are macros defined?
What is the correct way to name a macro with two arguments?
Which knowledge object is used to normalize field names to comply with the Splunk Common Information Model (CIM)?