When performing a regular expression (regex) field extraction using the Field Extractor (FX), what happens when the require option is used?
Answer(s): D
When using | timechart by host, which field is represented in the x-axis?
Which of the following is the correct way to use the datamodel command to search fields in the Web data model within the Web dataset?
Answer(s): A
Which of the following statements describe the command below? (Choose all that apply.)sourcetype=access_combined | transaction JSESSIONID
Answer(s): B,C,D
Which of the following searches will return events containing a tag named Privileged?
Answer(s): B
https://docs.splunk.com/Documentation/PCI/4.1.0/Install/PrivilegedUserActivity
Share your comments for Splunk SPLK-1002 exam with other users:
very nice content