Exam 2: Splunk Enterprise Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

When using timechart , how many fields can be listed after a by clause?

(Multiple Choice)
4.8/5
(36)

Which of the following statements describe the search below? (Choose all that apply.) index=main | transaction clientip host maxspan=30s maxpause=5s

(Multiple Choice)
4.9/5
(36)

Calculated fields can be based on which of the following?

(Multiple Choice)
4.8/5
(45)

When can a pipe follow a macro?

(Multiple Choice)
5.0/5
(38)

Information needed to create a GET workflow action includes which of the following? (Choose all that apply.)

(Multiple Choice)
4.8/5
(28)

What do events in a transaction have in common?

(Multiple Choice)
4.9/5
(35)

Which of the following statements describes the use of the Field Extractor (FX)?

(Multiple Choice)
4.7/5
(44)

By default, how is acceleration configured in the Splunk Common Information Model (CIM) add-on?

(Multiple Choice)
4.9/5
(33)

In which of the following scenarios is an event type more effective than a saved search?

(Multiple Choice)
4.8/5
(30)

Based on the macro definition shown below, what is the correct way to execute the macro in a search string? Based on the macro definition shown below, what is the correct way to execute the macro in a search string?

(Multiple Choice)
4.7/5
(37)

A data model consists of which three types of datasets?

(Multiple Choice)
4.8/5
(34)

In which Settings section are macros defined?

(Multiple Choice)
4.8/5
(40)

What is a limitation of searches generated by workflow actions?

(Multiple Choice)
4.8/5
(41)

Which of the following statements about macros is true? (Choose all that apply.)

(Multiple Choice)
4.7/5
(38)

Which of the following data models are included in the Splunk Common Information Model (CIM) add-on? (Choose all that apply.)

(Multiple Choice)
4.8/5
(29)

After manually editing a regular expression (regex), which of the following statements is true?

(Multiple Choice)
4.7/5
(29)

Which of the following commands support the same set of functions?

(Multiple Choice)
4.8/5
(31)

When creating a Search workflow action, which field is required?

(Multiple Choice)
4.9/5
(42)

A data model can consist of what three types of datasets?

(Multiple Choice)
4.7/5
(30)

Which of the following actions can the eval command perform?

(Multiple Choice)
4.8/5
(35)
Showing 41 - 60 of 79
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)