Splunk Core Certified Advanced Power User (SPLK-1004) – Quiz 1 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) If a nested macro expands to a search string that begins with a generating command, what additional syntax is needed? A. Double tick marks around the nested macro. B. A comma before the nested macro. C. Square brackets around the nested macro. D. A pipe character before the nested macro. 2 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) Which commands can run on both search heads and indexers? A. Transforming commands B. Centralized streaming commands C. Dataset processing commands D. Distributable streaming commands 3 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) How is a cascading input used? A. As part of a dashboard, but not in a form. B. Without token notation in the underlying XML. C. As a way to filter other input selections. D. As a default way to delete a user role. 4 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) What happens to panels with post-processing searches when their base search is refreshed? A. The panels are deleted. B. The panels are only refreshed if they have also been configured. C. The panels are refreshed automatically. D. Nothing happens to the panels. 5 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) What qualifies a report for acceleration? A. Fewer than 100k events in search results, with transforming commands used in the search string. B. More than 100k events in search results, with only a search command in the search string. C. More than 100k events in the search results, with a search and transforming command used in the search string. D. Fewer than 100k events in search results, with only a search and transaction command used in the search string. 6 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) What is an example of the simple XML syntax for a base search and its post-process search? A. , B. , C. , D. , 7 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) How can a lookup be referenced in an alert? A. Use the lookup dropdown in the alert configuration window. B. Follow a lookup with an alert command in the search bar. C. Run a search that uses a lookup and save as an alert. D. Upload a lookup file directly to the alert 8 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) How can form inputs impact dashboard panels using inline searches? A. A token in a search can be replaced by a form input value. B. Panels powered by an inline search require a minimum of one form input. C. Form inputs can not impact panels using inline searches. D. Adding a form input to a dashboard converts all panels to prebuilt panels 9 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) What file types does Splunk use to define geospatial lookups? A. GPX or GML files B. TXT files C. KMZ or KML files D. CSV files 10 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) What type of drilldown passes a value from a user click into another dashboard or external page? A. Visualization B. Event C. Dynamic D. Contextual 11 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) What order of incoming events must be supplied to the transaction command to ensure correct results? A. Reverse lexicographical order B. Ascending lexicographical order C. Ascending chronological order D. Reverse chronological order 12 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) Which statement about tsidx files is accurate? A. Splunk updates tsidx files every 30 minutes. B. Splunk removes outdated tsidx files every 5 minutes. C. A tsidx file consists of a lexicon and a posting list. D. Each bucket in each index may contain only one tsidx file. 13 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) Repeating JSON data structures within one event will be extracted as what type of fields? A. Single value B. Lexicographical C. Multivalue D. Mvindex 14 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) What default Splunk role can use the Log Event alert action? A. Power B. User C. can_delete D. Admin 15 / 15 Category: Splunk Core Certified Advanced Power User (SPLK-1004) When running a search, which Splunk component retrieves the individual results? A. Indexer B. Search head C. Universal forwarder D. Master node Your score is 0% Restart quiz Send feedback