Splunk SPLK-1002 Splunk Core Certified Power User Online Training
Splunk SPLK-1002 Online Training
The questions for SPLK-1002 were last updated at Nov 23,2024.
- Exam Code: SPLK-1002
- Exam Name: Splunk Core Certified Power User
- Certification Provider: Splunk
- Latest update: Nov 23,2024
This function of the stats command allows you to identify the number of values a field has.
- A . max
- B . distinct_count
- C . fields
- D . count
This function of the stats command allows you to return the sample standard deviation of a field.
- A . stdev
- B . dev
- C . count deviation
- D . by standarddev
Which of the following commands will show the maximum bytes?
- A . sourcetype=access_* | maximum totals by bytes
- B . sourcetype=access_* | avg (bytes)
- C . sourcetype=access_* | stats max(bytes)
- D . sourcetype=access_* | max(bytes)
Which of the following searches will show the number of categoryld used by each host?
- A . Sourcetype=access_* |sum bytes by host
- B . Sourcetype=access_* |stats sum(categorylD. by host
- C . Sourcetype=access_* |sum(bytes) by host
- D . Sourcetype=access_* |stats sum by host
This clause is used to group the output of a stats command by a specific name.
- A . Rex
- B . As
- C . List
- D . By
This function of the stats command allows you to return the middle-most value of field X.
- A . Median(X)
- B . Eval by X
- C . Fields(X)
- D . Values(X)
When a search returns __________, you can view the results as a list.
- A . a list of events
- B . transactions
- C . statistical values
Clicking a SEGMENT on a chart, ________.
- A . drills down for that value
- B . highlights the field value across the chart
- C . adds the highlighted value to the search criteria
Use this command to use lookup fields in a search and see the lookup fields in the field sidebar.
- A . inputlookup
- B . lookup
It is mandatory for the lookup file to have this for an automatic lookup to work.
- A . Source type
- B . At least five columns
- C . Timestamp
- D . Input filed