Which of the following statements describes the command below (select all that apply)
Sourcetype=access_combined | transaction JSESSIONID
A. An additional filed named maxspan is created.
B. An additional field named duration is created.
C. An additional field named eventcount is created.
D. Events with the same JSESSIONID will be grouped together into a single event.
The Splunk Common Information Model (CIM) is a collection of what type of knowledge object?
A. KV Store
B. Lookups
C. Saved searches
D. Data models
Field aliases are used to __________ data
A. clean
B. transform
C. calculate
D. normalize
When extracting fields, we may choose to use our own regular expressions
A. True
B. False
There are several ways to access the field extractor. Which option automatically identifies data type, source type, and sample event?
A. Event Actions > Extract Fields
B. Fields sidebar > Extract New Field
C. Settings > Field Extractions > New Field Extraction D. Settings > Field Extractions > Open Field Extraction
The limit attribute will___________.
A. override default of 10
B. only work with top command
C. override default of 20
D. override default of 15
This is what Splunk uses to categorize the data that is being indexed.
A. sourcetype
B. index
C. source
D. host
Which of the following transforming commands can be used with transactions?
A. chart, timechart, stats, eventstats
B. chart, timechart, stats, diff
C. chart, timeehart, datamodel, pivot
D. chart, timecha:t, stats, pivot
Which of the following are valid options to speed up reports? (Select all the apply.)
A. Edit permissions
B. Edit description
C. Edit acceleration
D. Edit schedule
Which of these is NOT a field that is automatically created with the transaction command?
A. maxcount
B. duration
C. eventcount