Splunk SPLK-1002 - Splunk Core Certified Power User Exam
By default, how is acceleration configured in the Splunk Common Information Model (CIM) add-on?
What does the Splunk Common Information Model (CIM) add-on include? (select all that apply)
Splunk alerts can be based on search that run______. (Select all that apply.)
Which search retrieves events with the event type web_errors?
Data model fields can be added using the Auto-Extracted method. Which of the following statements describe Auto-Extracted fields? (select all that apply)
The timechart command is an example of which of the following command types?
What information must be included when using the datamodel command?
Consider the the following search run over a time range of last 7 days:
index=web sourcetype=access_conbined | timechart avg(bytes) by product_nane
Which option is used to change the default time span so that results are grouped into 12 hour intervals?
Which knowledge object is used to normalize field names to comply with the Splunk Common Information Model (CIM)?
What is the correct format for naming a macro with multiple arguments?
