Free SPLK-1002 Exam Braindumps (page: 4)

Page 4 of 54

There are several ways to access the field extractor.
Which option automatically identifies the data type, source type, and sample event?

  1. Event Actions > Extract Fields
  2. Fields sidebar > Extract New Fields
  3. Settings > Field Extractions > New Field Extraction
  4. Settings > Field Extractions > Open Field Extractor

Answer(s): A


Reference:

https://docs.splunk.com/Documentation/Splunk/8.0.4/Knowledge/Managesearch- timefieldextractions



Which of the following statements would help a user choose between the transaction and stats
commands?

  1. stats can only group events using IP addresses.
  2. The transaction command is faster and more efficient.
  3. There is a 1000 event limitation with the transaction command.
  4. Use stats when the events need to be viewed as a single correlated event.

Answer(s): C


Reference:

https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/Transaction



By default, how is acceleration configured in the Splunk Common Information Model (CIM) add-on?

  1. Turned off.
  2. Turned on.
  3. Determined automatically based on the sourcetype.
  4. Determined automatically based on the data source.

Answer(s): A



Which of the following statements describe the Common Information Model (CIM)? (Choose all that apply.)

  1. CIM is a methodology for normalizing data.
  2. CIM can correlate data from different sources.
  3. The Knowledge Manager uses the CIM to create knowledge objects.
  4. CIM is an app that can coexist with other apps on a single Splunk deployment.

Answer(s): A,B,C






Post your Comments and Discuss Splunk® SPLK-1002 exam prep with other Community members:

SPLK-1002 Exam Discussions & Posts