Which of the following data model are included In the Splunk Common Information Model (CIM) add-on? (select all that apply)
Which of the following is the correct way to use the data model command to search field in the data model within the web dataset?
What functionality does the Splunk Common Information Model (CIM) rely on to normalize fields with different names?
Data model fields can be added using the Auto-Extracted method. Which of the following statements describe Auto-Extracted fields? (select all that apply)
After manually editing; a regular expression (regex), which of the following statements is true?
The Field Extractor (FX) is used to extract a custom field. A report can be created using this custom field. The created report can then be shared with other people in the organization. If another person in the organization runs the shared report and no results are returned, why might this be? (select all that apply)
Which of the following statements describes this search?
sourcetype=access_combined I transaction JSESSIONID | timechart avg (duration)
Which of the following searches show a valid use of macro? (Select all that apply)
Which of the following knowledge objects represents the output of an eval expression?
Based on the macro definition shown below, what is the correct way to execute the macro in a search string?
Which of the following workflow actions can be executed from search results? (select all that apply)
Which of the following searches will return events contains a tag name Privileged?
Which of the following statements about data models and pivot are true? (select all that apply)
A user wants to convert numeric field values to strings and also to sort on those values.
Which command should be used first, the eval or the sort?
Which of the following statements describes the command below (select all that apply)
Sourcetype=access_combined | transaction JSESSIONID
Which of the following statements describe the search string below?
| datamodel Application_State All_Application_State search
Which delimiters can the Field Extractor (FX) detect? (select all that apply)
Which of the following describes the Splunk Common Information Model (CIM) add-on?
Which of the following statements describe the search below? (select all that apply)
Index=main I transaction clientip host maxspan=30s maxpause=5s
Which of the following can be used with the eval command tostring function (select all that apply)
Data model are composed of one or more of which of the following datasets? (select all that apply.)
Which of the following expressions could be used to create a calculated field called gigabytes?
This function of the stats command allows you to identify the number of values a field has.
There are several ways to access the field extractor. Which option automatically identifies data type, source type, and sample event?
Using the Field Extractor (FX) tool, a value is highlighted to extract and give a name to a new field. Splunk has not successfully extracted that value from all appropriate events. What steps can be taken so Splunk successfully extracts the value from all appropriate events? (select all that apply)
Which of the following searches will show the number of categoryld used by each host?
What approach is recommended when using the Splunk Common Information Model (CIM) add-on to normalize data?
Which syntax will find events where the values for the 1 field match the values for the Renewal-MonthYear field?
What other syntax will produce exactly the same results as | chart count over vendor_action by user?
Consider the following search:
index=web sourcetype=access_combined
The log shows several events that share the same JSESSIONID value (SD470K92802F117). View the events as a group.
From the following list, which search groups events by JSESSIONID?
Which field extraction method should be selected for comma-separated data?
Which of the following describes this search?
New Search
'third_party_outages(EMEA,-24h)'
How is a Search Workflow Action configured to run at the same time range as the original search?
Which of the following is included with the Common Information Model (CIM) add-on?
Which of these stats commands will show the total bytes for each unique combination of page and server?
The macro weekly_sales (2) contains the search string:
index=games | eval ProductSales = $Price$ * $AmountSold$
Which of the following will return results?
Which of the following transforming commands can be used with transactions?
__________ datasets can be added to root dataset to narrow down the search