最新的Splunk Core Certified Power User - SPLK-1002免費考試真題
問題1
The eval command allows you to do which of the following? (Choose all that apply.)
正確答案: A,B,C,D
問題2
Which field will be used to populate the field if the productName and product:d fields have values for a given event?
| eval productINFO=coalesco(productName,productid)
| eval productINFO=coalesco(productName,productid)
正確答案: B
說明:(僅 VCESoft 成員可見)
問題3
Which of the following is a feature of the Pivot tool?
正確答案: C
說明:(僅 VCESoft 成員可見)
問題4
What does the following search do?


正確答案: A
說明:(僅 VCESoft 成員可見)
問題5
Which of the following knowledge objects can reference field aliases?
正確答案: B
說明:(僅 VCESoft 成員可見)
問題6
Which of the following objects can a calculated field use as a source?
正確答案: D
說明:(僅 VCESoft 成員可見)
問題7
How is a macro referenced in a search?
正確答案: C
說明:(僅 VCESoft 成員可見)
問題8
These allow you to categorize events based on search terms.
Select your answer.
Select your answer.
正確答案: D
問題9
Which of the following searches show a valid use of macro? (Select all that apply)
正確答案: B,C
說明:(僅 VCESoft 成員可見)
問題10
When should transaction be used?
正確答案: B
問題11
Select this in the fields sidebar to automatically pipe you search results to the rare command
正確答案: C
說明:(僅 VCESoft 成員可見)
問題12
Which command is used to create choropleth maps?
正確答案: C
問題13
Which of the following is true about Pivot?
正確答案: D
說明:(僅 VCESoft 成員可見)
問題14
What happens to the original field name when a field alias is created?
正確答案: D
說明:(僅 VCESoft 成員可見)