Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

SPLK-1004 Exam Dumps - Splunk Core Certified Advanced Power User Exam

Go to page:
Question # 17

A report named "Linux logins" populates a summary index with the search string sourcetype=linux_secure | sitop src_ip user. Which of the following correctly searches against the summary index for this data?

A.

index=summary sourcetype="linux_secure" | top src_ip user

B.

index=summary search_name="Linux logins" | top src_ip user

C.

index=summary search_name="Linux logins" | stats count by src_ip user

D.

index=summary sourcetype="linux_secure" | stats count by src_ip user

Full Access
Question # 18

When using a nested search macro, how can an argument value be passed to the inner macro?

A.

The argument value may be passed to the outer macro.

B.

An argument cannot be used with an inner nested macro.

C.

An argument cannot be used with an outer nested macro.

D.

The argument value must be specified in the outer macro.

Full Access
Question # 19

When should the fill_summary_index.py script be used?

A.

To create a summary index.

B.

To backfill gaps in a summary index.

C.

To reset a summary index that includes overlapping data.

D.

To populate a summary index from a saved report.

Full Access
Question # 20

Which of the following is true about themultikvcommand?

A.

Themultikvcommand derives field names from the last column in a table-formatted event.

B.

Themultikvcommand creates an event for each column in a table-formatted event.

C.

Themultikvcommand requires field names to be ALL CAPS whenmultitable=false.

D.

Themultikvcommand displays an event for each row in a table-formatted event.

Full Access
Question # 21

Which search generates a field with a value of "hello"?

A.

| makeresults field="hello"

B.

| makeresults | fields="hello"

C.

| makeresults | eval field="hello"

D.

| makeresults | eval field=make{"hello"}

Full Access
Question # 22

What is the function of the |s token filter?

A.

|s is not a valid token filter.

B.

To wrap a value in double quotes.

C.

To force no encoding to occur.

D.

To encode URL values.

Full Access
Question # 23

How can a lookup be referenced in an alert?

A.

Use the lookup dropdown in the alert configuration window.

B.

Follow a lookup with an alert command in the search bar.

C.

Run a search that uses a lookup and save as an alert.

D.

Upload a lookup file directly to the alert.

Full Access
Question # 24

When enabled, what drilldown action is performed when a visualization is clicked in a dashboard?

A.

A visualization is opened in a new window.

B.

Search results are refreshed for the selected visualization.

C.

Search results are refreshed for all panels in a dashboard.

D.

A search is opened in a new window.

Full Access
Go to page: