Free SPLK-1002 Exam Braindumps (page: 4)

Page 3 of 39

What is the correct syntax to search for a tag associated with a value on a specific fields?

  1. Tag-<field?
  2. Tag<filed(tagname.)
  3. Tag=<filed>::<tagname>
  4. Tag::<filed>=<tagname>

Answer(s): D



Which of the following statements describes macros?

  1. A macro is a reusable search string that must contain the full search.
  2. A macro is a reusable search string that must have a fixed time range.
  3. A macro Is a reusable search string that may have a flexible time range.
  4. A macro Is a reusable search string that must contain only a portion of the search.

Answer(s): C



Calculated fields can be based on which of the following?

  1. Tags
  2. Extracted fields
  3. Output fields for a lookup
  4. Fields generated from a search string

Answer(s): B



Which of the following statements describes field aliases?

  1. Field alias names replace the original field name.
  2. Field aliases can be used in lookup file definitions.
  3. Field aliases only normalize data across sources and sourcetypes.
  4. Field alias names are not case sensitive when used as part of a search.

Answer(s): A






Post your Comments and Discuss Splunk® SPLK-1002 exam with other Community members:

SPLK-1002 Discussions & Posts