Free SPLK-1001 Exam Braindumps (page: 20)

Page 19 of 62

The command shown here does witch of the following: Command: |outputlookup products.csv

  1. Writes search results to a file named products.csv
  2. Returns the contents of a file named products.csv

Answer(s): A



Which of the following are not true about lookups? (Select all that apply.)

  1. Lookups can be time based
  2. Search results can be used to populate a lookup table
  3. Splunk DB Connect can be used to populate a lookup table from relational databases
  4. Output from a script can be used to populate a lookup table
  5. Lookup have a 10mg maximum size limit

Answer(s): E



Lookups allow you to overwrite your raw event.

  1. True
  2. False

Answer(s): A



It is mandatory for the lookup file to have this for an automatic lookup to work.

  1. Source type
  2. At least five columns
  3. Timestamp
  4. Input filed

Answer(s): D






Post your Comments and Discuss Splunk® SPLK-1001 exam with other Community members:

SPLK-1001 Discussions & Posts