Exam 2: Splunk Enterprise Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

What other syntax will produce exactly the same results as | chart count over vendor_action by user ?

(Multiple Choice)
4.8/5
(39)

Which of the following knowledge objects represents the output of an eval expression?

(Multiple Choice)
5.0/5
(28)

Which of the following searches show a valid use of a macro? (Choose all that apply.)

(Multiple Choice)
4.8/5
(37)

Which of the following statements describe the command below? (Choose all that apply.) sourcetype=access_combined | transaction JSESSIONID

(Multiple Choice)
4.8/5
(38)

If no value is specified with the fillnull command, what default value will be used?

(Multiple Choice)
4.8/5
(38)

What is the relationship between data models and pivots?

(Multiple Choice)
4.8/5
(34)

In most large Splunk environments, what is the most efficient command that can be used to group events by fields?

(Multiple Choice)
4.8/5
(32)

Which type of visualization shows relationships between discrete values in three dimensions?

(Multiple Choice)
4.9/5
(37)

What are the two parts of a root event dataset?

(Multiple Choice)
4.9/5
(38)

Which of the following statements describe data model acceleration? (Choose all that apply.)

(Multiple Choice)
4.8/5
(36)

When using the transaction command, what does the argument maxspan do?

(Multiple Choice)
4.8/5
(37)

A user wants to convert numeric field values to strings and also to sort on those values. Which command should be used first, the eval or the sort ?

(Multiple Choice)
4.9/5
(33)

What does the fillnull command replace null values with, if the value argument is not specified?

(Multiple Choice)
4.9/5
(41)

Which workflow action method can be used when the action type is set to link?

(Multiple Choice)
4.8/5
(28)

When using the Field Extractor (FX), which of the following delimiters will work? (Choose all that apply.)

(Multiple Choice)
4.8/5
(46)

Which of the following statements describe calculated fields? (Choose all that apply.)

(Multiple Choice)
4.8/5
(50)

Which of the following statements would help a user choose between the transaction and stats commands?

(Multiple Choice)
4.8/5
(41)

What information must be included when using the datamodel command?

(Multiple Choice)
5.0/5
(36)

There are several ways to access the field extractor. Which option automatically identifies the data type, source type, and sample event?

(Multiple Choice)
4.8/5
(37)

Which of the following statements describes POST workflow actions?

(Multiple Choice)
4.8/5
(40)
Showing 21 - 40 of 79
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)