Free SPLK-1002 Exam Braindumps (page: 5)

Page 4 of 39

Which delimiters can the Field Extractor (FX) detect? (select all that apply)

  1. Tabs
  2. Pipes
  3. Spaces
  4. Commas

Answer(s): B,C,D



Which of the following searches show a valid use of macro? (Select all that apply)

  1. index=main source=mySource oldField=* | 'makeMyField(oldField)' | table _time newField
  2. index=main source=mySource oldField=* | state if ('makeMyField(oldField ' ) | table _time
  3. index=main source=mySource oldField=* | eval newField= 'makeMyField(oldField) ' | table _time
  4. index=main source=mySource oldField=* | "'newField('makeMyField(oldField) " ) ' " | table _time

Answer(s): A,C



Which of the following statements describe GET workflow actions?

  1. GET workflow actions must be configured with POST arguments.
  2. Configuration of GET workflow actions includes choosing a sourcetype.
  3. Label names for GET workflow actions must include a field name surrounded by dollar signs.
  4. GET workflow actions can be configured to open the URT link in the current window or in a new window

Answer(s): D



Which of the following actions can the eval command perform?

  1. Remove fields from results.
  2. Create or replace an existing field.
  3. Group transactions by one or more fields.
  4. Save SPL commands to be reused in other searches.

Answer(s): B






Post your Comments and Discuss Splunk® SPLK-1002 exam with other Community members:

SPLK-1002 Discussions & Posts