Labour Day Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Splunk Core Certified Power User Exam Question and Answers

Splunk Core Certified Power User Exam

Last Update May 3, 2024
Total Questions : 257

We are offering FREE SPLK-1002 Splunk exam questions. All you do is to just go and sign up. Give your details, prepare SPLK-1002 free exam questions and then go for complete pool of Splunk Core Certified Power User Exam test questions that will help you more.

SPLK-1002 pdf

SPLK-1002 PDF

$35  $99.99
SPLK-1002 Engine

SPLK-1002 Testing Engine

$42  $119.99
SPLK-1002 PDF + Engine

SPLK-1002 PDF + Testing Engine

$56  $159.99
Questions 1

Which of the following statements describe the search string below?

| datamodel Application_State All_Application_State search

Options:

A.  

Evenrches would return a report of sales by state.

B.  

Events will be returned from the data model named Application_State.

C.  

Events will be returned from the data model named All_Application_state.

D.  

No events will be returned because the pipe should occur after the datamodel command

Discussion 0
Questions 2

Based on the macro definition shown below, what is the correct way to execute the macro in a search string?

Options:

A.  

Convert_sales (euro, €, 79)”

B.  

Convert_sales (euro, €, .79)

C.  

Convert_sales ($euro,$€$,s79$

D.  

Convert_sales ($euro, $€$,S,79$)

Discussion 0
Questions 3

A space is an implied _____ in a search string.

Options:

A.  

OR

B.  

AND

C.  

()

D.  

NOT

Discussion 0
Questions 4

The Field Extractor (FX) is used to extract a custom field. A report can be created using this custom field. The created report can then be shared with other people in the organization. If another person in the organization runs the shared report and no results are returned, why might this be? (select all that apply)

Options:

A.  

Fast mode is enabled.

B.  

The dashboard is private.

C.  

The extraction is private-

D.  

The person in the organization running the report does not have access to the index.

Discussion 0
Questions 5

After manually editing; a regular expression (regex), which of the following statements is true?

Options:

A.  

Changes made manually can be reverted in the Field Extractor (FX) UI.

B.  

It is no longer possible to edit the field extraction in the Field Extractor (FX) UI.

C.  

It is not possible to manually edit a regular expression (regex) that was created using the Field Extractor (FX) UI.

D.  

The Field Extractor (FX) UI keeps its own version of the field extraction in addition to the one that was manually edited.

Discussion 0
Questions 6

Data model fields can be added using the Auto-Extracted method. Which of the following statements describe Auto-Extracted fields? (select all that apply)

Options:

A.  

Auto-Extracted fields can be hidden in Pivot.

B.  

Auto-Extracted fields can have their data type changed.

C.  

Auto-Extracted fields can be given a friendly name for use in Pivot.

D.  

Auto-Extracted fields can be added if they already exist in the dataset with constraints.

Discussion 0
Questions 7

What is the relationship between data models and pivots?

Options:

A.  

Data models provide the datasets for pivots.

B.  

Pivots and data models have no relationship.

C.  

Pivots and data models are the same thing.

D.  

Pivots provide the datasets for data models.

Discussion 0
Questions 8

Which are valid ways to create an event type? (select all that apply)

Options:

A.  

By using the searchtypes command in the search bar.

B.  

By editing the event_type stanza in the props.conf file.

C.  

By going to the Settings menu and clicking Event Types > New.

D.  

By selecting an event in search results and clicking Event Actions > Build Event Type.

Discussion 0
Questions 9

Which of the following statements about data models and pivot are true? (select all that apply)

Options:

A.  

They are both knowledge objects.

B.  

Data models are created out of datasets called pivots.

C.  

Pivot requires users to input SPL searches on data models.

D.  

Pivot allows the creation of data visualizations that present different aspects of a data model.

Discussion 0
Questions 10

When creating a Search workflow action, which field is required?

Options:

A.  

Search string

B.  

Data model name

C.  

Permission setting

D.  

An eval statement

Discussion 0
Questions 11

Which of the following actions can the eval command perform?

Options:

A.  

Remove fields from results.

B.  

Create or replace an existing field.

C.  

Group transactions by one or more fields.

D.  

Save SPL commands to be reused in other searches.

Discussion 0
Questions 12

Which of the following knowledge objects represents the output of an eval expression?

Options:

A.  

Eval fields

B.  

Calculated fields

C.  

Field extractions

D.  

Calculated lookups

Discussion 0
Questions 13

What are the two parts of a root event dataset?

Options:

A.  

Fields and variables.

B.  

Fields and attributes.

C.  

Constraints and fields.

D.  

Constraints and lookups.

Discussion 0
Questions 14

Which of the following statements describe data model acceleration? (select all that apply)

Options:

A.  

Root events cannot be accelerated.

B.  

Accelerated data models cannot be edited.

C.  

Private data models cannot be accelerated.

D.  

You must have administrative permissions or the accelerate_dacamodel capability to accelerate a data model.

Discussion 0
Questions 15

Which of the following statements describes an event type?

Options:

A.  

A log level measurement: info, warn, error.

B.  

A knowledge object that is applied before fields are extracted.

C.  

A field for categorizing events based on a search string.

D.  

Either a log, a metric, or a trace.

Discussion 0
Questions 16

When would transaction be used instead of stats?

Options:

A.  

To group events based on a single field value.

B.  

To see results of a calculation.

C.  

To have a faster and more efficient search.

D.  

To group events based on start/end values.

Discussion 0
Questions 17

When using the Field Extractor (FX), which of the following delimiters will work? (select all that apply)

Options:

A.  

Tabs

B.  

Pipes

C.  

Colons

D.  

Spaces

Discussion 0
Questions 18

If a search returns ____________ it can be viewed as a chart.

Options:

A.  

timestamps

B.  

statistics

C.  

events

D.  

keywords

Discussion 0
Questions 19

Which workflow uses field values to perform a secondary search?

Options:

A.  

POST

B.  

Action

C.  

Search

D.  

Sub-Search

Discussion 0
Questions 20

What functionality does the Splunk Common Information Model (CIM) rely on to normalize fields with different names?

Options:

A.  

Macros.

B.  

Field aliases.

C.  

The rename command.

D.  

CIM does not work with different names for the same field.

Discussion 0
Questions 21

What is required for a macro to accept three arguments?

Options:

A.  

The macro's name ends with (3).

B.  

The macro's name starts with (3).

C.  

The macro's argument count setting is 3 or more.

D.  

Nothing, all macros can accept any number of arguments.

Discussion 0
Questions 22

Use the dedup command to _____.

Options:

A.  

Rename a field in the index

B.  

remove duplicate values

C.  

provide an additional alias for the field that can D.be used in the search criteria

Discussion 0
Questions 23

This function of the stats command allows you to return the middle-most value of field X.

Options:

A.  

Median(X)

B.  

Eval by X

C.  

Fields(X)

D.  

Values(X)

Discussion 0
Questions 24

What does the following search do?

Options:

A.  

Creates a table of the total count of users and split by corndogs.

B.  

Creates a table of the total count of mysterymeat corndogs split by user.

C.  

Creates a table with the count of all types of corndogs eaten split by user.

D.  

Creates a table that groups the total number of users by vegetarian corndogs.

Discussion 0
Questions 25

Which of the following knowledge objects can reference field aliases?

Options:

A.  

Calculated fields, lookups, event types, and tags.

B.  

Calculated fields and tags only.

C.  

Calculated fields and event types only.

D.  

Calculated fields, lookups, event types, and extracted fields.

Discussion 0
Questions 26

When defining a macro, what are the required elements?

Options:

A.  

Name and arguments.

B.  

Name and a validation error message.

C.  

Name and definition.

D.  

Definition and arguments.

Discussion 0
Questions 27

Which of the following describes the I transaction command?

Options:

A.  

It is an SPL command that groups at least two events together based on shared values in selected fields.

B.  

It allows an exchange of data from one Splunk index to another Splunk index.

C.  

It is an SPL command that groups events together with shared values in selected fields.

D.  

It allows an exchange of data from one Splunk system to another Splunk system.

Discussion 0
Questions 28

What fields does the transaction command add to the raw events? (select all that apply)

Options:

A.  

count

B.  

duration

C.  

eventcount

D.  

transaction id

Discussion 0
Questions 29

When would a user select delimited field extractions using the Field Extractor (FX)?

Options:

A.  

When a log file has values that are separated by the same character, for example, commas.

B.  

When a log file contains empty lines or comments.

C.  

With structured files such as JSON or XML.

D.  

When the file has a header that might provide information about its structure or format.

Discussion 0
Questions 30

A field alias is created where field1—fieid2 and the Overwrite Field Values checkbox is selected.

What happens if an event only contains values for fieid1?

Options:

A.  

field2 values are removed from the events.

B.  

field1 and field2 values are merged.

C.  

field2 values are unchanged.

D.  

field2 values are replaced with the value of the field1.

Discussion 0
Questions 31

By default, how is acceleration configured in the Splunk Common Information Model (CIM) add-on?

Options:

A.  

Turned off

B.  

Turned on

C.  

Determined automatically based on the sourcetype.

D.  

Determined automatically based on the data source.

Discussion 0
Questions 32

Which statement is true?

Options:

A.  

Pivot is used for creating datasets.

B.  

Data models are randomly structured datasets.

C.  

Pivot is used for creating reports and dashboards.

D.  

In most cases, each Splunk user will create their own data model.

Discussion 0
Questions 33

Which of the following describes this search?

New Search

'third_party_outages(EMEA,-24h)'

Options:

A.  

This search will find all events for the third_party_outages event type that have "EMEA" or "-24h" in the raw event data.

B.  

This search will run the third_party_outages saved search and filter for events containing "EMEA" and "-24h" in the raw event data.

C.  

This search will run the third_party_outages macro and pass the arguments EMEA and -24h to the macro definition.

D.  

This search will find all events in the third_party_outages index with the tags EMEA and -24h.

Discussion 0
Questions 34

The time range specified for a historical search defines the ____________ .------questionable on ans

Options:

A.  

Amount of data shown on the timeline as data streams in

B.  

Amount of data fetched from index matching that time range

C.  

Time range for the static results

Discussion 0
Questions 35

What does the fillnull command replace null values with, if the value argument is not specified?

Options:

A.  

0

B.  

N/A

C.  

NaN

D.  

NULL

Discussion 0
Questions 36

Which of these search strings is NOT valid:

Options:

A.  

index=web status=50* | chart count over host, status

B.  

index=web status=50* | chart count over host by status

C.  

index=web status=50* | chart count by host, status

Discussion 0
Questions 37

Which of the following statements describes the use of the Field Extractor (FX)?

Options:

A.  

The Field Extractor automatically extracts all fields at search time.

B.  

The Field Extractor uses PERL to extract fields from the raw events.

C.  

Fields extracted using the Field Extractor persist as knowledge objects.

D.  

Fields extracted using the Field Extractor do not persist and must be defined for each search.

Discussion 0
Questions 38

Which of the following statements describe the search below? (select all that apply)

Index=main I transaction clientip host maxspan=30s maxpause=5s

Options:

A.  

Events in the transaction occurred within 5 seconds.

B.  

It groups events that share the same clientip and host.

C.  

The first and last events are no more than 5 seconds apart.

D.  

The first and last events are no more than 30 seconds apart.

Discussion 0
Questions 39

Which of the following eval command function is valid?

Options:

A.  

Int ()

B.  

Count ( )

C.  

Print ()

D.  

Tostring ()

Discussion 0
Questions 40

Which of the following statements describes the command below (select all that apply)

Sourcetype=access_combined | transaction JSESSIONID

Options:

A.  

An additional filed named maxspan is created.

B.  

An additional field named duration is created.

C.  

An additional field named eventcount is created.

D.  

Events with the same JSESSIONID will be grouped together into a single event.

Discussion 0
Questions 41

During the validation step of the Field Extractor workflow:

Select your answer.

Options:

A.  

You can remove values that aren't a match for the field you want to define

B.  

You can validate where the data originated from

C.  

You cannot modify the field extraction

Discussion 0
Questions 42

If there are fields in the data with values that are " " or empty but not null, which of the following would add a value?

Options:

A.  

| eval notNULL = if(isnull (notNULL), “0” notNULL)

B.  

| eval notNULL = if(isnull (notNULL), “0”

C.  

| eval notNULL = “” | nullfill value=0 notNULL

D.  

| eval notNULL = “” fillnull value=0 notNULL

Discussion 0
Questions 43

The transaction command allows you to __________ events across multiple sources

Options:

A.  

duplicate

B.  

correlate

C.  

persist

D.  

tag

Discussion 0
Questions 44

A macro has another macro nested within it, and this inner macro requires an argument. How can the user pass this argument into the SPL?

Options:

A.  

An argument can be passed through the outer macro.

B.  

An argument can be passed to the outer macro by nesting parentheses.

C.  

There is no way to pass an argument to the inner macro.

D.  

An argument can be passed to the inner macro by nesting parentheses.

Discussion 0
Questions 45

Using the export function, you can export search results as __________.( Select all that apply)

Options:

A.  

Xml

B.  

Json

C.  

Html

D.  

A php file

Discussion 0
Questions 46

The fields sidebar does not show________. (Select all that apply.)

Options:

A.  

interesting fields

B.  

selected fields

C.  

all extracted fields

Discussion 0
Questions 47

When extracting fields, we may choose to use our own regular expressions

Options:

A.  

True

B.  

False

Discussion 0
Questions 48

Which of the following objects can a calculated field use as a source?

Options:

A.  

An alias of a field.

B.  

A field added by an automatic lookup.

C.  

The tag field.

D.  

The eventtype field.

Discussion 0
Questions 49

In the Field Extractor, when would the regular expression method be used?

Options:

A.  

When events contain JSON data.

B.  

When events contain comma-separated data.

C.  

When events contain unstructured data.

D.  

When events contain table-based data.

Discussion 0
Questions 50

Which of the following examples would use a POST workflow action?

Options:

A.  

Perform an external IP lookup based on a domain value found in events.

B.  

Use the field values in an HTTP error event to create a new ticket in an external system.

C.  

Launch secondary Splunk searches that use one or more field values from selected events.

D.  

Open a web browser to look up an HTTP status code.

Discussion 0
Questions 51

Which of the following statements describes POST workflow actions?

Options:

A.  

Configuration of a POST workflow action includes choosing a sourcetype.

B.  

POST workflow actions can be configured to send email to the URI location.

C.  

By default, POST workflow action are shown in both the event and field menus.

D.  

POST workflow actions can be configured to send POST arguments to the URI location.

Discussion 0
Questions 52

Which of the following are valid options to speed up reports? (Select all the apply.)

Options:

A.  

Edit permissions

B.  

Edit description

C.  

Edit acceleration

D.  

Edit schedule

Discussion 0
Questions 53

Which of the following is true about Pivot?

Options:

A.  

Users can save reports from Pivot.

B.  

Users cannot share visualizations created with Pivot.

C.  

Users must use SPL to find events in a Pivot.

D.  

Users cannot create visualizations with Pivot.

Discussion 0
Questions 54

This clause is used to group the output of a stats command by a specific name.

Options:

A.  

Rex

B.  

As

C.  

List

D.  

By

Discussion 0
Questions 55

What will you learn from the results of the following search?

sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)

Options:

A.  

The average time elapsed during each transaction for all transactions

B.  

The average time for each event within each transaction

C.  

The average time between each transaction

Discussion 0
Questions 56

The macro weekly_sales (2) contains the search string:

index—games I eval Product Sales = $price$ $AmountS01d$

Which of the following will return results?

Options:

A.  

‘weekly_sales(3.99, 10) '

B.  

‘weekly_sales($3.99$, $10$)

C.  

'weekly_sales (3.99, 10)

D.  

‘weekly_sales(3)

Discussion 0
Questions 57

Which search retrieves events with the event type web_errors?

Options:

A.  

tag=web_errors

B.  

eventtype=web_errors

C.  

eventtype "web errors"

D.  

eventtype (web_errors)

Discussion 0
Questions 58

Which field extraction method should be selected for comma-separated data?

Options:

A.  

Regular expression

B.  

Delimiters

C.  

eval expression

D.  

table extraction

Discussion 0
Questions 59

Which of these is NOT a field that is automatically created with the transaction command?

Options:

A.  

maxcount

B.  

duration

C.  

eventcount

Discussion 0
Questions 60

What information must be included when using the datamodel command?

Options:

A.  

status field

B.  

Multiple indexes

C.  

Data model field name.

D.  

Data model dataset name.

Discussion 0
Questions 61

Which of the following statements describe GET workflow actions?

Options:

A.  

GET workflow actions must be configured with POST arguments.

B.  

Configuration of GET workflow actions includes choosing a sourcetype.

C.  

Label names for GET workflow actions must include a field name surrounded by dollar signs.

D.  

GET workflow actions can be configured to open the URT link in the current window or in a new window

Discussion 0
Questions 62

Which of the following is the correct way to use the data model command to search field in the data model within the web dataset?

Options:

A.  

| datamodel web search | filed web *

B.  

| Search datamodel web web | filed web*

C.  

| datamodel web web field | search web*

D.  

Datamodel=web | search web | filed web*

Discussion 0
Questions 63

Calculated fields can be based on which of the following?

Options:

A.  

Tags

B.  

Extracted fields

C.  

Output fields for a lookup

D.  

Fields generated from a search string

Discussion 0
Questions 64

What does the Splunk Common Information Model (CIM) add-on include? (select all that apply)

Options:

A.  

Custom visualizations

B.  

Pre-configured data models

C.  

Fields and event category tags

D.  

Automatic data model acceleration

Discussion 0
Questions 65

Which of the following file formats can be extracted using a delimiter field extraction?

Options:

A.  

CSV

B.  

PDF

C.  

XML

D.  

JSON

Discussion 0
Questions 66

Which of the following statements describes this search?

sourcetype=access_combined I transaction JSESSIONID | timechart avg (duration)

Options:

A.  

This is a valid search and will display a timechart of the average duration, of each transaction event.

B.  

This is a valid search and will display a stats table showing the maximum pause among transactions.

C.  

No results will be returned because the transaction command must include the startswith and endswith options.

D.  

No results will be returned because the transaction command must be the last command used in the search pipeline.

Discussion 0
Questions 67

Which of the following statements is true, especially in large environments?

Options:

A.  

Use the scats command when you next to group events by two or more fields.

B.  

The stats command is faster and more efficient than the transaction command

C.  

The transaction command is faster and more efficient than the stats command.

D.  

Use the transaction command when you want to see the results of a calculation.

Discussion 0
Questions 68

Which of the following statements describes field aliases?

Options:

A.  

Field alias names replace the original field name.

B.  

Field aliases can be used in lookup file definitions.

C.  

Field aliases only normalize data across sources and sourcetypes.

D.  

Field alias names are not case sensitive when used as part of a search.

Discussion 0
Questions 69

Which of the following statements describes Search workflow actions?

Options:

A.  

By default. Search workflow actions will run as a real-time search.

B.  

Search workflow actions can be configured as scheduled searches,

C.  

The user can define the time range of the search when created the workflow action.

D.  

Search workflow actions cannot be configured with a search string that includes the transaction command

Discussion 0
Questions 70

Which of the following describes the Splunk Common Information Model (CIM) add-on?

Options:

A.  

The CIM add-on uses machine learning to normalize data.

B.  

The CIM add-on contains dashboards that show how to map data.

C.  

The CIM add-on contains data models to help you normalize data.

D.  

The CIM add-on is automatically installed in a Splunk environment.

Discussion 0
Questions 71

Which of the following statements about event types is true? (select all that apply)

Options:

A.  

Event types can be tagged.

B.  

Event types must include a time range,

C.  

Event types categorize events based on a search.

D.  

Event types can be a useful method for capturing and sharing knowledge.

Discussion 0
Questions 72

Which of the following can be used with the eval command tostring function (select all that apply)

Options:

A.  

‘’hex’’

B.  

‘’commas’’

C.  

‘’Decimal’’

D.  

‘’duration’’

Discussion 0
Questions 73

Which of the following statements describes macros?

Options:

A.  

A macro is a reusable search string that must contain the full search.

B.  

A macro is a reusable search string that must have a fixed time range.

C.  

A macro Is a reusable search string that may have a flexible time range.

D.  

A macro Is a reusable search string that must contain only a portion of the search.

Discussion 0
Questions 74

Data model are composed of one or more of which of the following datasets? (select all that apply.)

Options:

A.  

Events datasets

B.  

Search datasets

C.  

Transaction datasets

D.  

Any child of event, transaction, and search datasets

Discussion 0
Questions 75

When performing a regular expression (regex) field extraction using the Field Extractor (FX), what happens when the require option is used?

Options:

A.  

The regex can no longer be edited.

B.  

The field being extracted will be required for all future events.

C.  

The events without the required field will not display in searches.

D.  

Only events with the required string will be included in the extraction.

Discussion 0
Questions 76

A calculated field maybe based on which of the following?

Options:

A.  

Lookup tables

B.  

Extracted fields

C.  

Regular expressions

D.  

Fields generated within a search string

Discussion 0
Questions 77

What do events in a transaction have In common?

Options:

A.  

All events In a transaction must have the same timestamp.

B.  

All events in a transaction must have the same sourcetype.

C.  

All events in a transaction must have the exact same set of fields.

D.  

All events in a transaction must be related by one or more fields.

Discussion 0