Free SPLK-1002 Exam Braindumps (page: 16)

Page 15 of 39

A field alias has been created based on an original field. A search without any transforming commands is then executed in Smart Mode. Which field name appears in the results?

  1. Both will appear in the All Fields list, but only if the alias is specified in the search.
  2. Both will appear in the Interesting Fields list, but only if they appear in at least 20 percent of events.
  3. The original field only appears in All Fields list and the alias only appears in the Interesting Fields list.
  4. The alias only appears in the All Fields list and the original field only appears in the Interesting Fields list.

Answer(s): B



What functionality does the Splunk Common Information Model (CIM) rely on to normalize fields with different names?

  1. Macros.
  2. Field aliases.
  3. The rename command.
  4. CIM does not work with different names for the same field.

Answer(s): B



What is required for a macro to accept three arguments?

  1. The macro's name ends with (3).
  2. The macro's name starts with (3).
  3. The macro's argument count setting is 3 or more.
  4. Nothing, all macros can accept any number of arguments.

Answer(s): A



Which of the following workflow actions can be executed from search results? (select all that apply)

  1. GET
  2. POST
  3. LOOKUP
  4. Search

Answer(s): A,B,D






Post your Comments and Discuss Splunk® SPLK-1002 exam with other Community members:

SPLK-1002 Discussions & Posts