Splunk Core Certified Power User Exam Questions and Answers
Which of the following Statements about macros is true? (select all that apply)
Calculated fields can be based on which of the following?
Which of the following is the correct way to use the data model command to search field in the data model within the web dataset?
Which group of users would most likely use pivots?
Which of the following searches show a valid use of macro? (Select all that apply)
What are the two parts of a root event dataset?
To identify all of the contributing events within a transaction that contains at least one REJECT event, which syntax is correct?
Which of the following can be used with the eval command tostring function (select all that apply)
In what order arc the following knowledge objects/configurations applied?
Which of the following describes the Splunk Common Information Model (CIM) add-on?
Which of the following statements describes Search workflow actions?
Which of the following data model are included In the Splunk Common Information Model (CIM) add-on? (select all that apply)
Which of the following workflow actions can be executed from search results? (select all that apply)
Which of the following statements describes POST workflow actions?
What is the correct syntax to search for a tag associated with a value on a specific fields?
Which of the following file formats can be extracted using a delimiter field extraction?
Which of the following statements describe the search string below?
| datamodel Application_State All_Application_State search
Data model are composed of one or more of which of the following datasets? (select all that apply.)
Which of the following statements describe the search below? (select all that apply)
Index=main I transaction clientip host maxspan=30s maxpause=5s
Which of the following statements about event types is true? (select all that apply)
A field alias has been created based on an original field. A search without any transforming commands is then executed in Smart Mode. Which field name appears in the results?
What is required for a macro to accept three arguments?
Which delimiters can the Field Extractor (FX) detect? (select all that apply)
How does a user display a chart in stack mode?
Which of the following searches will return events contains a tag name Privileged?
Based on the macro definition shown below, what is the correct way to execute the macro in a search string?
What functionality does the Splunk Common Information Model (CIM) rely on to normalize fields with different names?
A space is an implied _____ in a search string.
Which of the following statements describes field aliases?
A calculated field maybe based on which of the following?
A user wants to convert numeric field values to strings and also to sort on those values.
Which command should be used first, the eval or the sort?
After manually editing; a regular expression (regex), which of the following statements is true?
When should you use the transaction command instead of the scats command?
Which of the following statements about data models and pivot are true? (select all that apply)
Which one of the following statements about the search command is true?
Which of the following statements describe data model acceleration? (select all that apply)
What do events in a transaction have In common?
Which of the following statements describes macros?
When creating a Search workflow action, which field is required?
Which workflow action method can be used the action type is set to link?
Using the export function, you can export search results as __________.( Select all that apply)
Which is not a comparison operator in Splunk
What is the Splunk Common Information Model (CIM)?
Which syntax is used to represent an argument in a macro definition?
When using | timchart by host, which filed is representted in the x-axis?
If a calculated field has the same name as an extracted field, what happens to the extracted field?
Which statement is true?
How are arguments defined within the macro search string?
When is a GET workflow action needed?
When extracting fields, we may choose to use our own regular expressions
The eval command allows you to do which of the following? (Choose all that apply.)
When creating a data model, which root dataset requires at least one constraint?
Which search string would only return results for an event type called success ful_purchases?
When should transaction be used?
What will you learn from the results of the following search?
sourcetype=cisco_esa | transaction mid, dcid, icid | timechart avg(duration)
It is mandatory for the lookup file to have this for an automatic lookup to work.
Which of the following is true about the Splunk Common Information Model (CIM)?
Why are tags useful in Splunk?
When a search returns __________, you can view the results as a list.
Which of the following expressions could be used to create a calculated field called gigabytes?
What is the correct format for naming a macro with multiple arguments?
A user runs the following search:
index—X sourcetype=Y I chart count (domain) as count, sum (price) as sum by product, action usenull=f useother—f
Which of the following table headers match the order this command creates?
By default search results are not returned in ________ order.
Which of the following describes the I transaction command?
How is an event type created from the search window? (select all that apply)
How could the following syntax for the chart command be rewritten to remove the OTHER category? (select all that apply)
Given the following eval statement:
...| eval fieldl - if(isnotnull(fieldl),fieldl,0), field2 = if(isnull
Which of the following is the equivalent using f ilinull?
What does the fillnull command replace null values with, if the value argument is not specified?
Which of the following commands support the same set of functions?
The eval command 'if' function requires the following three arguments (in order):
Why would the following search produce multiple transactions instead of one?
What is the correct syntax to find events associated with a tag?
We can use the rename command to _____ (Select all that apply.)
Complete the search, …. | _____ failure>successes
Data models are composed of one or more of which of the following datasets? (select all that apply)
What other syntax will produce exactly the same results as | chart count over vendor_action by user?
Which of the following knowledge objects can reference field aliases?