A user runs the following search:
index--X sourcetype=Y I chart count (domain) as count, sum (price) as sum by product, action usenull=f useother--f
Which of the following table headers match the order this command creates?
A. The chart command does not allow for multiple statistical functions.
B. Product, sum: addtocart, sum: remove, sum: purchase, count: addtocart, count: remove, count: purchase
C. Product, count: addtocart, count: remove, count: purchase, sum: addtocart, sum: remove, sum: purchase
D. Count: product, sum: product, count: action, sum: action
A report scheduled to run every 15 mins. but takes 17 mins. to complete is in danger of being_____.
A. skipped or deferred
B. automatically accelerated
C. deleted
D. all of the above
By default search results are not returned in ________ order.
A. Chronological
B. Reverser chronological
C. ASCIE
D. Alphabetical
Where are the descriptions of the data models that come with the Splunk Common Information Model (CIM) Add-on documented?
A. Search and reporting user manual.
B. CIM Add-on manual.
C. Pivot users manual.
D. Datamodel command reference guide.
When would transaction be used instead of stats?
A. To see results of a calculation.
B. To group events based on start/end values.
C. To have a faster and more efficient search.
D. To group events based on a single field value.
A user wants to create a new field alias for a field that appears in two sourcetypes.
How many field aliases need to be created?
A. One.
B. Two.
C. It depends on whether the original fields have the same name.
D. It depends on whether the two sourcetypes are associated with the same index.
This function of the stats command allows you to return the middle-most value of field X.
A. Median(X)
B. Eval by X
C. Fields(X)
D. Values(X)
Which of the following data models are included in the Splunk Common Information Model (CIM) add-on? (select all that apply)
A. User permissions
B. Alerts
C. Databases
D. Email
Which knowledge Object does the Splunk Common Information Model (CIM) use to normalize data. in addition to field aliases, event types, and tags?
A. Macros
B. Lookups
C. Workflow actions
D. Field extractions
Which of these is NOT a field that is automatically created with the transaction command?
A. maxcount
B. duration
C. eventcount