Splunk SPLK-1002 Splunk Core Certified Power User Online Training
Splunk SPLK-1002 Online Training
The questions for SPLK-1002 were last updated at Nov 23,2024.
- Exam Code: SPLK-1002
- Exam Name: Splunk Core Certified Power User
- Certification Provider: Splunk
- Latest update: Nov 23,2024
The fields sidebar does not show________. (Select all that apply.)
- A . interesting fields
- B . selected fields
- C . all extracted fields
Splunk alerts can be based on search that run______. (Select all that apply.)
- A . in real-time
- B . on a regular schedule
- C . and have no matching events
Which of the following about reports is/are true?
- A . Reports are knowledge objects.
- B . Reports can be scheduled.
- C . Reports can run a script.
- D . All of the above.
Select this in the fields sidebar to automatically pipe you search results to the rare command
- A . events with this field
- B . rare values
- C . top values by time
- D . top values
A report scheduled to run every 15 mins. but takes 17 mins. to complete is in danger of being_____.
- A . skipped or deferred
- B . automatically accelerated
- C . deleted
- D . all of the above
Which of the following are valid options to speed up reports? (Select all the apply.)
- A . Edit permissions
- B . Edit description
- C . Edit acceleration
- D . Edit schedule
Which of the following statements are true for this search? (Select all that apply.)
SEARCH: sourcetype=access* |fields action productld status
- A . is looking for all events that include the search terms: fields AND action AND productld AND status
- B . users the table command to improve performance
- C . limits the fields are extracted
- D . returns a table with 3 columns
Use the dedup command to _____.
- A . Rename a field in the index
- B . remove duplicate values
- C . provide an additional alias for the field that can
- D . be used in the search criteria
We can use the rename command to _____ (Select all that apply.)
- A . Change indexed fields
- B . Exclude fields from our search results
- C . Extract new fields from our data using regular expressions
- D . Give a field a new name at search time
The limit attribute will___________.
- A . override default of 10
- B . only work with top command
- C . override default of 20
- D . override default of 15