New Year Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Splunk SPLK-1004 - Splunk Core Certified Advanced Power User Exam

Page: 2 / 4
Total 120 questions

Which of the following can be used to access external lookups?

A.

Perl and Python

B.

Python and Ruby

C.

Perl and binary executable

D.

Python and binary executable

When and where do search debug messages appear to help with troubleshooting views?

A.

In the Dashboard Editor, while the search is running.

B.

In the Search Job Inspector, after the search completes.

C.

In the Search Job Inspector, while the search is running.

D.

In the Dashboard Editor, after the search completes.

What is one way to troubleshoot dashboards?

A.

Create an HTML panel using tokens to verify that they are set.

B.

Run the | previous_searches command to your SPL queries.

C.

Go to the Troubleshooting dashboard of the Searching and Reporting app.

D.

Delete the dashboard and start over.

How is regex passed to the makemv command?

A.

makemv must be preceded by the erex command.

B.

It is specified by the delim argument.

C.

It is specified by the tokenizer argument.

D.

makemv must be preceded by the rex command.

When enabled, what drilldown action is performed when a visualization is clicked in a dashboard?

A.

A visualization is opened in a new window.

B.

Search results are refreshed for the selected visualization.

C.

Search results are refreshed for all panels in a dashboard.

D.

A search is opened in a new window.

How can form inputs impact dashboard panels using inline searches?

A.

Panels powered by an inline search require a minimum of one form input.

B.

Form inputs cannot impact panels using inline searches.

C.

Adding a form input to a dashboard converts all panels to prebuilt panels.

D.

A token in a search can be replaced by a form input value.

Which statement about.tsidxfiles is accurate?

A.

A.tsidxfile consists of a lexicon and a posting list.

B.

Splunk removes outdated.tsidxfiles every 5 minutes.

C.

Splunk updates.tsidxfiles every 30 minutes.

D.

Each bucket in each index may contain only one.tsidxfile.

What does it mean when a command is run and the is_exact column is 0?

A.

The distinct count of values for that field is exactly 0.

B.

The distinct count of fields in the field summary is 1.

C.

The distinct count of values in that field is approximated.

D.

The distinct count of values for that field is exact.

If a search contains a subsearch, what is the order of execution?

A.

The order of execution depends on whether either search uses a stats command.

B.

The inner search executes first.

C.

The outer search executes first.

D.

The two searches are executed in parallel.

What happens to panels with post-processing searches when their base search is refreshed?

A.

The panels are deleted.

B.

The panels are only refreshed if they have also been configured.

C.

The panels are refreshed automatically.

D.

Nothing happens to the panels.