Exam 2: Splunk Enterprise Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Data model fields can be added using the Auto-Extracted method. Which of the following statements describe Auto-Extracted fields? (Choose all that apply.)

Free
(Multiple Choice)
4.8/5
(47)
Correct Answer:
Verified

B

What does the Splunk Common Information Model (CIM) add-on include? (Choose all that apply.)

Free
(Multiple Choice)
4.9/5
(40)
Correct Answer:
Verified

B,D

Which of the following statements about tags is true?

Free
(Multiple Choice)
4.9/5
(37)
Correct Answer:
Verified

B

Which of the following can be used with the eval command tostring function? (Choose all that apply.)

(Multiple Choice)
4.8/5
(35)

Which of the following is a function of the Splunk Common Information Model (CIM)?

(Multiple Choice)
4.8/5
(31)

Which of the following statements about event types is true? (Choose all that apply.)

(Multiple Choice)
4.9/5
(43)

Which workflow uses field values to perform a secondary search?

(Multiple Choice)
4.8/5
(43)

When using | timechart by host , which field is represented in the x-axis?

(Multiple Choice)
4.9/5
(35)

Which Knowledge Object does the Splunk Common Information Model (CIM) use to normalize data, in addition to field aliases, event types, and tags?

(Multiple Choice)
4.9/5
(34)

What does the transaction command do?

(Multiple Choice)
4.9/5
(36)

Which of the following searches would create a graph similar to the one below? Which of the following searches would create a graph similar to the one below?

(Multiple Choice)
5.0/5
(37)

In what order are the following knowledge objects/configurations applied?

(Multiple Choice)
4.8/5
(38)

What is the correct syntax to search for a tag associated with a value on a specific field?

(Multiple Choice)
4.8/5
(35)

When multiple event types with different color values are assigned to the same event, what determines the color displayed for the event?

(Multiple Choice)
4.9/5
(42)

A calculated field may be based on which of the following?

(Multiple Choice)
4.7/5
(32)

Which of the following statements is true, especially in large environments?

(Multiple Choice)
4.9/5
(40)

Which are valid ways to create an event type? (Choose all that apply.)

(Multiple Choice)
5.0/5
(40)

Data models are composed of one or more of which of the following datasets? (Choose all that apply.)

(Multiple Choice)
4.9/5
(40)

Which group of users would most likely use pivots?

(Multiple Choice)
4.7/5
(41)

When using the timechart command, how can a user group the events into buckets based on time?

(Multiple Choice)
4.9/5
(36)
Showing 1 - 20 of 79
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)