Free SPLK-1002 Exam Braindumps (page: 6)

Page 5 of 39

When performing a regular expression (regex) field extraction using the Field Extractor (FX), what happens when the require option is used?

  1. The regex can no longer be edited.
  2. The field being extracted will be required for all future events.
  3. The events without the required field will not display in searches.
  4. Only events with the required string will be included in the extraction.

Answer(s): D



Which of the following statements describe calculated fields? (select all that apply)

  1. Calculated fields can be used in the search bar.
  2. Calculated fields can be based on an extracted field.
  3. Calculated fields can only be applied to host and sourcetype.
  4. Calculated fields are shortcuts for performing calculations using the eval command.

Answer(s): A,B,D



When creating a Search workflow action, which field is required?

  1. Search string
  2. Data model name
  3. Permission setting
  4. An eval statement

Answer(s): A



Which of the following can be used with the eval command tostring function (select all that apply)

  1. `'hex''
  2. `'commas''
  3. `'Decimal''
  4. `'duration''

Answer(s): A,B,D






Post your Comments and Discuss Splunk® SPLK-1002 exam with other Community members:

SPLK-1002 Discussions & Posts