Which of the following statements describe calculated fields? (select all that apply)
What functionality does the Splunk Common Information Model (CIM) rely on to normalize fields with different names?
Which of the following searches will return events contains a tag name Privileged?
To identify all of the contributing events within a transaction that contains at least one REJECT event, which syntax is correct?
Which of the following statements describe the search below? (select all that apply)
Index=main I transaction clientip host maxspan=30s maxpause=5s
Which of the following file formats can be extracted using a delimiter field extraction?
Based on the macro definition shown below, what is the correct way to execute the macro in a search string?
Which of the following can be used with the eval command tostring function (select all that apply)
A field alias has been created based on an original field. A search without any transforming commands is then executed in Smart Mode. Which field name appears in the results?
Which of the following statements about data models and pivot are true? (select all that apply)
What does the Splunk Common Information Model (CIM) add-on include? (select all that apply)
When multiple event types with different color values are assigned to the same event, what determines the color displayed for the events?
Data model are composed of one or more of which of the following datasets? (select all that apply.)
Which of the following statements about event types is true? (select all that apply)
Which of the following statements describe the search string below?
| datamodel Application_State All_Application_State search
Which of the following data model are included In the Splunk Common Information Model (CIM) add-on? (select all that apply)
This function of the stats command allows you to return the sample standard deviation of a field.
The eval command allows you to do which of the following? (Choose all that apply.)
Which of the following is one of the pre-configured data models included in the Splunk Common Information Model (CIM) add-on?
For choropleth maps,splunk ships with the following KMZ files (select all that apply)
Which of the following search control will not re-rerun the search? (Select all that apply.)
Which knowledge object is used to normalize field names to comply with the Splunk Common Information Model (CIM)?
How is a Search Workflow Action configured to run at the same time range as the original search?
Select this in the fields sidebar to automatically pipe you search results to the rare command
A user runs the following search:
index—X sourcetype=Y I chart count (domain) as count, sum (price) as sum by product, action usenull=f useother—f
Which of the following table headers match the order this command creates?
The Splunk Common Information Model (CIM) is a collection of what type of knowledge object?
Which of the following search modes automatically returns all extracted fields in the fields sidebar?
Which of the following is a function of the Splunk Common Information Model (CIM)?
When creating a data model, which root dataset requires at least one constraint?
Which of the following is true about the Splunk Common Information Model (CIM)?
Consider the the following search run over a time range of last 7 days:
index=web sourcetype=access_conbined | timechart avg(bytes) by product_nane
Which option is used to change the default time span so that results are grouped into 12 hour intervals?
Consider the following search:
index=web sourcetype=access_combined
The log shows several events that share the same JSESSIONID value (SD470K92802F117). View the events as a group.
From the following list, which search groups events by JSESSIONID?
What happens when a user edits the regular expression (regex) field extraction generated in the Field Extractor (FX)?
Which of the following searches will return events containing a tag named Privileged?
Which of the following data models are included in the Splunk Common Information Model (CIM) add-on? (select all that apply)
Consider the following search:
index=web sourcetype=access_corabined
The log shows several events that share the same jsesszonid value (SD462K101O2F267). View the events as a group.
From the following list, which search groups events by jSSESSIONID?
The macro weekly_sales (2) contains the search string:
index=games | eval ProductSales = $Price$ * $AmountSold$
Which of the following will return results?
After manually editing; a regular expression (regex), which of the following statements is true?
In which of the following scenarios is an event type more effective than a saved search?