Free SPLK-1002 Exam Braindumps (page: 7)

Page 5 of 54

Which of the following knowledge objects represents the output of an eval expression?

  1. Eval fields
  2. Calculated fields
  3. Field extractions
  4. Calculated lookups

Answer(s): B


Reference:

https://docs.splunk.com/Splexicon:Calculatedfield



What do events in a transaction have in common?

  1. All events in a transaction must have the same timestamp.
  2. All events in a transaction must have the same sourcetype.
  3. All events in a transaction must have the exact same set of fields.
  4. All events in a transaction must be related by one or more fields.

Answer(s): D


Reference:

https://docs.splunk.com/Documentation/Splunk/8.0.3/Knowledge/Abouttransactions



Which delimiters can the Field Extractor (FX) detect? (Choose all that apply.)

  1. Tabs
  2. Pipes
  3. Spaces
  4. Commas

Answer(s): A,B,C



A data model consists of which three types of datasets?

  1. Constraint, field, value.
  2. Events, searches, transactions.
  3. Field extraction, regex, delimited.
  4. Transaction, session ID, metadata.

Answer(s): B


Reference:

https://docs.splunk.com/Splexicon:Datamodeldataset






Post your Comments and Discuss Splunk® SPLK-1002 exam prep with other Community members:

SPLK-1002 Exam Discussions & Posts