Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

Splunk SPLK-1004 Splunk Core Certified Advanced Power User Exam Practice Test

Page: 1 / 7
Total 70 questions

Splunk Core Certified Advanced Power User Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$42  $119.99

PDF Study Guide

  • Product Type: PDF Study Guide
$36.75  $104.99
Question 1

Which syntax is used when referencing multiple CSS files in a view?

Options:

A.

B.

C.

D.

Question 2

A report named "Linux logins" populates a summary index with the search string sourcetype=linux_secure| sitop src_ip user. Which of the following correctly

searches against the summary index for this data?

Options:

A.

index=summary sourcetype="linux_secure" | top src_ip user

B.

index=summary search_name="Linux logins" | top src_ip user

C.

index=summary search_name="Linux logins" | stats count by src_ip user

D.

index=summary sourcetype="linux_secure" | stats count by src_ip user

Question 3

What happens to panels with post-processing searches when their base search Is refreshed?

Options:

A.

The parcels are deleted.

B.

The panels are only refreshed If they have also been configured.

C.

The panels are refreshed automatically.

D.

Nothing happens to the panels.

Question 4

How is regex passed to the makemv command?

Options:

A.

makemv be preceded by the erex command.

B.

It is specified by the delim argument.

C.

It Is specified by the tokenizer argument.

D.

Makemv must be preceded by the rex command.

Question 5

Which of the following has a schema or structure embedded in the data itself?

Options:

A.

Dark data

B.

Unstructured data

C.

Embedded data

D.

Self-describing data

Question 6

What order of incoming events must be supplied to the transaction command to ensure correct results?

Options:

A.

Reverse lexicographical order

B.

Ascending lexicographical order

C.

Ascending chronological order

D.

Reverse chronological order

Question 7

Which of the following can be used to access external lookups?

Options:

A.

Perl and Python

B.

Python and Ruby

C.

Perl and binary executable

D.

Python and binary executable

Question 8

Which command processes a template for a set of related fields?

Options:

A.

bin

B.

xyseries

C.

foreach

D.

untable

Question 9

Which field Is requited for an event annotation?

Options:

A.

annotation_category

B.

_time

C.

eventype

D.

annotation_label

Question 10

What is the correct hierarchy of XML elements in a dashboard panel?

Options:

A.

B.

C.

D.

Question 11

Which statement about tsidx files is accurate?

Options:

A.

Splunk updates tsidx files every 30 minutes.

B.

Splunk removes outdated tsidx files every 5 minutes.

C.

A tsidx file consists of a lexicon and a posting list.

D.

Each bucket in each index may contain only one tsidx file.

Question 12

What is the value of base lispy in the Search Job Inspector for the search index-sales clientip-170.192.178.10?

Options:

A.

[ index::sales 192 AND 10 AMD 178 AND 170 ]

B.

[ index::sales AND 469 10 702 390 ]

C.

[ 192 AND 10 AND 178 AND 170 Index::sales ]

D.

[ AND 10 170 178 192 Index::sales ]

Question 13

When and where do search debug messages appear to help with troubleshooting views?

Options:

A.

In the Dashboard Editor, while the search is running.

B.

In the Search Job Inspector, after the search completes.

C.

In the Search Job Inspector, while the search is running.

D.

In the Dashboard Editor, after the search completes.

Question 14

Why use the tstats command?

Options:

A.

As an alternative to the summary command.

B.

To generate statistics on indexed fields.

C.

To generate an accelerated datamodel.

D.

To generate statistics on search-time fields.

Question 15

What file types does Splunk use to define geospatial lookups?

Options:

A.

GPX or GML files

B.

TXT files

C.

KMZ or KML files

D.

CSV files

Question 16

Which of the following is accurate about cascading inputs?

Options:

A.

They can be reset by an event handler.

B.

The final input has no impact on previous inputs.

C.

Only the final input of the sequence can supply a token to searches.

D.

Inputs added to panels can not participate.

Question 17

What does the query | makeresults generate?

Options:

A.

A timestamp

B.

A results field

C.

An error message

D.

The results of the previously run search.

Question 18

What are the four types of event actions?

Options:

A.

stats, target, set, and unset

B.

stats, target, change, and clear

C.

eval, link, change, and clear

D.

eval, link, set, and unset

Question 19

How can a lookup be referenced in an alert?

Options:

A.

Use the lookup dropdown in the alert configuration window.

B.

Follow a lookup with an alert command in the search bar.

C.

Run a search that uses a lookup and save as an alert.

D.

Upload a lookup file directly to the alert.

Question 20

Which of the following functions' primary purpose is to convert epoch time to a string format?

Options:

A.

tostring

B.

strptime

C.

tonumber

D.

strftime

Question 21

How is a cascading input used?

Options:

A.

As part of a dashboard, but not in a form.

B.

Without notation in the underlying. XML.

C.

As a way to filter other input selections.

D.

As a default way to delete a user role.

Page: 1 / 7
Total 70 questions