Splunk
SPLK-1004
Q1:
What does using the tstats command with summariesonly=false do?
○
A
Returns results from only non-summarized data.○
B
Returns results from both summarized and non-summarized data.○
C
Prevents the use of wildcard characters in aggregate functions.○
D
Returns no results.
Splunk
SPLK-1004
Q2:
What does the query | makeresults generate?
○
A
A timestamp○
B
A results field○
C
An error message○
D
The results of the previously run search
Splunk
SPLK-1004
Q3:
When running a search, which Splunk component retrieves the individual results?
○
A
Indexer○
B
Search head○
C
Universal forwarder○
D
Master node
Splunk
SPLK-1004
Q4:
What type of drilldown passes a value from a user click into another dashboard or external page?
○
A
Visualization○
B
Event○
C
Dynamic○
D
Contextual
Splunk
SPLK-1004
Q5:
What order of incoming events must be supplied to the transaction command to ensure correct results?
○
A
Reverse lexicographical order○
B
Ascending lexicographical order○
C
Ascending chronological order○
D
Reverse chronological order