After manually editing; a regular expression (regex), which of the following statements is true?

After manually editing; a regular expression (regex), which of the following statements is true?A . Changes made manually can be reverted in the Field Extractor (FX) UC . It is no longer possible to edit the field extraction in the Field Extractor (FX) UE . It is not possible to...

September 11, 2021 No Comments READ MORE +

Which command should be used first, the eval or the sort?

A user wants to convert numeric field values to strings and also to sort on those values. Which command should be used first, the eval or the sort?A . It doesn't matter whether eval or sort is used first.B . Convert the numeric to a string with eval first, then...

September 11, 2021 No Comments READ MORE +

Which of the following searches will return events contains a tag name Privileged?

Which of the following searches will return events contains a tag name Privileged?A . Tag= PrivB . Tag= Pri*C . Tag= Priv*D . Tag= PrivilegedView AnswerAnswer: B Explanation: Reference: https://docs.splunk.com/Documentation/PCI/4.1.0/Install/PrivilegedUserActivity

September 11, 2021 1 Comment READ MORE +

Data model are composed of one or more of which of the following datasets? (select all that apply.)

Data model are composed of one or more of which of the following datasets? (select all that apply.)A . Events datasetsB . Search datasetsC . Transaction datasetsD . Any child of event, transaction, and search datasetsView AnswerAnswer: A,B,C Explanation: Reference: https://docs.splunk.com/Documentation/Splunk/8.0.3/Knowledge/Aboutdatamodels

September 10, 2021 No Comments READ MORE +

When multiple event types with different color values are assigned to the same event, what determines the color displayed for the events?

When multiple event types with different color values are assigned to the same event, what determines the color displayed for the events?A . RankB . WeightC . PriorityD . PrecedenceView AnswerAnswer: C Explanation: Reference: https://docs.splunk.com/Documentation/SplunkCloud/8.0.2003/Knowledge/Defineeventtypes

September 10, 2021 No Comments READ MORE +

When using the Field Extractor (FX), which of the following delimiters will work? (select all that apply)

When using the Field Extractor (FX), which of the following delimiters will work? (select all that apply)A . TabsB . PipesC . ColonsD . SpacesView AnswerAnswer: A,B,D Explanation: Reference: https://docs.splunk.com/Documentation/Splunk/8.0.3/Knowledge/FXSelectMethodstep https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Separate-on-Colon/m-p/29751

September 9, 2021 No Comments READ MORE +

What does the transaction command do?

What does the transaction command do?A . Groups a set of transactions based on time.B . Creates a single event from a group of events.C . Separates two events based on one or more values.D . Returns the number of credit card transactions found in the event logs.View AnswerAnswer: B

September 9, 2021 No Comments READ MORE +

What are the two parts of a root event dataset?

What are the two parts of a root event dataset?A . Fields and variables.B . Fields and attributes.C . Constraints and fields.D . Constraints and lookups.View AnswerAnswer: C Explanation: Reference: https://docs.splunk.com/Documentation/SplunkLight/7.3.5/GettingStarted/Designdatamodelobjects

September 9, 2021 No Comments READ MORE +

Which of the following statements describe data model acceleration? (select all that apply)

Which of the following statements describe data model acceleration? (select all that apply)A . Root events cannot be accelerated.B . Accelerated data models cannot be edited.C . Private data models cannot be accelerated.D . You must have administrative permissions or the accelerate_dacamodel capability to accelerate a data model.View AnswerAnswer: B,C,D

September 9, 2021 No Comments READ MORE +

Which of the following statements describe the Common Information Model (QM)? (select all that apply)

Which of the following statements describe the Common Information Model (QM)? (select all that apply)A . CIM is a methodology for normalizing data.B . CIM can correlate data from different sources.C . The Knowledge Manager uses the CIM to create knowledge objects.D . CIM is an app that can coexist...

September 8, 2021 No Comments READ MORE +