QuestionQ1
Creating and Using Workflow ActionsWhich default Splunk role is permitted to use the Log Event alert action?
- A Power
- B User
- C can_delete
- D Admin
QuestionQ2
Creating Data ModelsWhat makes a report eligible for acceleration?
- A Fewer than 100k events in search results, with transforming commands used in the search string.
- B More than 100k events in search results, with only a search command in the search string.
- C More than 100k events in the search results, with a search and transforming command used in the search string.
- D Fewer than 100k events in search results, with only a search and transaction command used in the search string.
Community Discussion
QuestionQ3
Creating and Using MacrosWhen a nested macro expands into a search string that starts with a generating command, what extra syntax is required?
- A Double tick marks around the nested macro.
- B A comma before the nested macro.
- C Square brackets around the nested macro.
- D A pipe character before the nested macro.
Community Discussion
QuestionQ4
Creating and Managing FieldsWhich of the following are possible string results returned by the typeof function?
- A True, False, Unknown
- B Number, String, Bool
- C Number, String, Null
- D Field, Value, Lookup
Community Discussion
QuestionQ5
Creating and Using Workflow ActionsWhich capability must a power user have to create a Log Event alert action?
- A edit_search_server
- B edit_udp
- C edit_tcp
- D edit_alerts
Community Discussion