Exam 2: Splunk Enterprise Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Which of the following searches would return a report of sales by product_name ?

(Multiple Choice)
4.8/5
(35)

A user wants to create a new field alias for a field that appears in two sourcetypes. How many field aliases need to be created?

(Multiple Choice)
4.9/5
(33)

Which delimiters can the Field Extractor (FX) detect? (Choose all that apply.)

(Multiple Choice)
4.9/5
(42)

Which of the following statements describe GET workflow actions?

(Multiple Choice)
4.6/5
(27)

Which one of the following statements about the search command is true?

(Multiple Choice)
4.8/5
(31)

Where are the results of eval commands stored?

(Multiple Choice)
4.8/5
(40)

When performing a regular expression (regex) field extraction using the Field Extractor (FX), what happens when the require option is used?

(Multiple Choice)
4.8/5
(38)

How does a user display a chart in stack mode?

(Multiple Choice)
4.9/5
(46)

Which of the following searches will return events containing a tag named Privileged ?

(Multiple Choice)
4.8/5
(45)

Which of the following statements describe the search string below? | datamodel Application_State All_Application_State search

(Multiple Choice)
4.9/5
(39)

When should transaction be used?

(Multiple Choice)
4.9/5
(44)

Which of the following is the correct way to use the datamodel command to search fields in the Web data model within the dataset?

(Multiple Choice)
4.8/5
(39)

Which of the following statements describe the Common Information Model (CIM)? (Choose all that apply.)

(Multiple Choice)
4.9/5
(47)

Which statement is true?

(Multiple Choice)
4.8/5
(39)

The eval command allows you to do which of the following? (Choose all that apply.)

(Multiple Choice)
4.7/5
(38)

Which of the following statements describes macros?

(Multiple Choice)
4.8/5
(41)

What does the following search do? index=corndog type= mysterymeat action=eaten | stats count as corndog_count by user

(Multiple Choice)
4.8/5
(31)

Given the macro definition below, what should be entered into the Name and Arguments fields to correctly configure the macro? Given the macro definition below, what should be entered into the Name and Arguments fields to correctly configure the macro?

(Multiple Choice)
4.9/5
(32)

To identify all of the contributing events within a transaction that contain at least one REJECT event, which syntax is correct?

(Multiple Choice)
4.7/5
(35)
Showing 61 - 79 of 79
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)