Sign In
Home/Splunk/SPLK-1002/Free questions

SPLK-1002 — Free Practice Questions

10 free sample questions from a bank of 273, with the correct answers and explanations. No signup required — start practising right now.

1Which one of the following statements about the search command is true?
  • It does not allow the use of wildcards.
  • It treats field values in a case-sensitive manner.
  • It can only be used at the beginning of the search pipeline.
  • It behaves exactly like search strings before the first pipe.
Answer: D
2Which of the following statements would help a user choose between the transaction and stats commands?
  • stats can only group events using IP addresses.
  • The transaction command is faster and more efficient.
  • There is a 1000 event limitation with the transaction command.
  • Use stats when the events need to be viewed as a single correlated event.
Answer: C
3What is the correct syntax to find events associated with a tag?
  • tag: =
  • tags=
  • tags: =
  • tag=
Answer: D
4Which of the following is true about the Splunk Common Information Model (CIM)?
  • The CIM contains 28 pre-configured datasets.
  • The data models included in the CIM are configured with data model acceleration turned on.
  • The data models included in the CIM are configured with data model acceleration turned off.
  • The CIM is an app that needs to run on the indexer.
Answer: C
5Consider the following search run over a time range of last 7 days: index=web sourcetype=access_combined | timechart avg(bytes) by product_name Which option is used to change the default time span so that results are grouped into 12 hour intervals?
  • timespan=12
  • span=12h
  • timespan=12h
  • span=12
Answer: B
6When would transaction be used instead of stats?
  • To have a faster and more efficient search.
  • To see results of a calculation.
  • To group events based on start/end values.
  • To group events based on a single field value.
Answer: C
7Given the following eval statement: ... | eval field1 = if(isnotnull(fieid1),field1,0), field2 = if(isnull Which of the following is the equivalent using fillnull?
  • There is no equivalent expression using fillnull
  • ... | fillnull values=(0,"NO-VALUE") fields=(field1,field2)
  • ... | fillnull field1|' fillnull value="NO-VALUE" field2
  • ... | fillnull value=0 field1 | fillnull field2
Answer: C
8The Splunk Common Information Model (CIM) is a collection of what type of knowledge object?
  • Saved searches
  • Lookups
  • KV Store
  • Data models
Answer: D
9How is a Search Workflow Action configured to run at the same time range as the original search?
  • Select the "Use the same time range as the search that created the field listing" checkbox.
  • Set the earliest time to match the original search.
  • Select the same time range from the time-range picker.
  • Select the "Overwrite time range with the original search" checkbox.
Answer: A
10A calculated field is a shortcut for performing repetitive, long, or complex transformations using which of the following commands?
  • transaction
  • eval
  • lookup
  • stats
Answer: B

Want the full bank of 273 questions for SPLK-1002? See all practice exams.