Free SPLK-1002 Exam Braindumps (page: 9)

Page 8 of 39

Which of the following statements describes this search?

sourcetype=access_combined I transaction JSESSIONID | timechart avg (duration)

  1. This is a valid search and will display a timechart of the average duration, of each transaction event.
  2. This is a valid search and will display a stats table showing the maximum pause among transactions.
  3. No results will be returned because the transaction command must include the startswith and endswith options.
  4. No results will be returned because the transaction command must be the last command used in the search pipeline.

Answer(s): A



What is the relationship between data models and pivots?

  1. Data models provide the datasets for pivots.
  2. Pivots and data models have no relationship.
  3. Pivots and data models are the same thing.
  4. Pivots provide the datasets for data models.

Answer(s): A



A calculated field maybe based on which of the following?

  1. Lookup tables
  2. Extracted fields
  3. Regular expressions
  4. Fields generated within a search string

Answer(s): B



A user wants to convert field values to string and also to sort on those value. Which command should be used first, the eval or the sort?

  1. It doesn't matter whether eval or sort is used first.
  2. Convert the numeric to a string with eval first, then sort.
  3. Use sort first, then convert the numeric to a string with eval.
  4. You cannot use the sort command and the eval command on the same field.

Answer(s): B






Post your Comments and Discuss Splunk® SPLK-1002 exam with other Community members:

SPLK-1002 Discussions & Posts