최신Splunk Core Certified Advanced Power User - SPLK-1004무료샘플문제
문제1
Which of the following can be used to access external lookups?
Which of the following can be used to access external lookups?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제2
How can the erex and rex commands be used in conjunction to extract fields?
How can the erex and rex commands be used in conjunction to extract fields?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제3
When should summary indexing be used?
When should summary indexing be used?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제4
The question asks what happens when you use thestatscommand withsummariesonly=false. Let's analyze each option:
The question asks what happens when you use thestatscommand withsummariesonly=false. Let's analyze each option:
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제5
Assuming a standard time zone across the environment, what syntax will always return events from between 2:
00 AM and 5:00 AM?
Assuming a standard time zone across the environment, what syntax will always return events from between 2:
00 AM and 5:00 AM?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제6
What capability does a power user need to create a Log Event alert action?
What capability does a power user need to create a Log Event alert action?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제7
When should the fill_summary_index.py script be used?
When should the fill_summary_index.py script be used?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제8
Consider the following search:
(index=_internal log group=tcpin connections) earliest
| stats count as _count by sourceHost guid fwdType version
| eventstats dc(sourceHost) as dc_sourceHost by guid
| where dc_sourceHost > 1
| fields - dc_sourceHost
| xyseries guid fwdType sourceHost
| search guid="00507345-CE09-4A5E-428-D3E8718CB065"
| appendpipe [ stats count | eval "Duplicate GUID" = if(count==0, "Yes", "No") ] Which of the following are transforming commands?
Consider the following search:
(index=_internal log group=tcpin connections) earliest
| stats count as _count by sourceHost guid fwdType version
| eventstats dc(sourceHost) as dc_sourceHost by guid
| where dc_sourceHost > 1
| fields - dc_sourceHost
| xyseries guid fwdType sourceHost
| search guid="00507345-CE09-4A5E-428-D3E8718CB065"
| appendpipe [ stats count | eval "Duplicate GUID" = if(count==0, "Yes", "No") ] Which of the following are transforming commands?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제9
How is a cascading input used?
How is a cascading input used?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제10
Which of the following is true about the preview feature and macros?
Which of the following is true about the preview feature and macros?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)