Free SPLK-1002 Exam Braindumps (page: 2)

Page 1 of 39

Given the macro definition below, what should be entered into the Name and Arguments fileds to correctly configured the macro?

  1. The macro name is sessiontracker and the argument are action, JESSION.
  2. The macro name is sessiontracker (2) and the action JESSIONID
  3. The macro name is sessiontracker and the argument are sectional ,$ JESSIONIDS.
  4. The macro name is sessiontracker (2) and the argument are $action ,$JESSIONIDS.

Answer(s): B



Which of the following searches will return events contains a tag name Privileged?

  1. Tag= Priv
  2. Tag= Priv*
  3. Tag= Priv*
  4. Tag= Privileged

Answer(s): D



Which of the following is the correct way to use the data model command to search field in the data model within the web dataset?

  1. | datamodel web search | filed web *
  2. | Search datamodel web web | filed web*
  3. | datamodel web web field | search web*
  4. Datamodel=web | search web | filed web*

Answer(s): A



Data model are composed of one or more of which of the fo-owing datasets? (select all that apply.)

  1. Events datasets
  2. Search datasets
  3. Transaction datasets
  4. Any child of event, transaction, and search datasets

Answer(s): A,B,C






Post your Comments and Discuss Splunk® SPLK-1002 exam with other Community members:

SPLK-1002 Discussions & Posts