Information needed to create a GET workflow action includes which of the following? (Choose all that apply.)
Answer(s): A,B,C
https://docs.splunk.com/Documentation/Splunk/8.0.3/Knowledge/SetupaGETworkflowaction
Which of the following can be used with the eval command tostring function? (Choose all that apply.)
Answer(s): A,B,D
Which of the following searches show a valid use of a macro? (Choose all that apply.)
Answer(s): A,C
A user wants to convert numeric field values to strings and also to sort on those values. Which command should be used first, the eval or the sort?
Answer(s): C
Which Knowledge Object does the Splunk Common Information Model (CIM) use to normalize data, in addition to field aliases, event types, and tags?
Answer(s): B,D
https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime
Share your comments for Splunk SPLK-1002 exam with other users:
very nice content