Stack #4078237
Quiz yourself by thinking what should be in
each of the black spaces below before clicking
on it to display the answer.
Help!
|
|
||||
---|---|---|---|---|---|
show | • A knowledge object that applies information structure to raw data
• Can be used by the Pivot interface to generate reports and dashboard panels
• Must contain at least one of each dataset: Events, Searches, and Transactions
🗑
|
||||
show | Dataset Name
🗑
|
||||
show | Eval Expression
🗑
|
||||
show | ascending
🗑
|
||||
Which of the following do all event datasets contain? Select all that apply. • Constraints • Children • Fields • Purchases | show 🗑
|
||||
Information needed to create a GET workflow action includes which of the following? (Choose all that apply.) | show 🗑
|
||||
show | • A. "hex"
• B. "commas"
• D. "duration"
🗑
|
||||
Which of the following searches show a valid use of a macro? | show 🗑
|
||||
A user wants to convert numeric field values to strings and also to sort on those values. | show 🗑
|
||||
Which Knowledge Object does the Splunk Common Information Model (CIM) use to normalize data, in addition to field aliases, event types, and tags? • A. Macros • B. Lookups • C. Workflow actions • D. Field extractions | show 🗑
|
||||
show | • Accelerated data models cannot be edited.
• Private data models cannot be accelerated.
• You must have administrative permissions or the accelerate_datamodel capability to accelerate a data model.
🗑
|
||||
How does a user display a chart in stack mode? • A. By using the stack command. • B. By turning on the Use Trellis Layout option. • C. By changing Stack Mode in the Format menu. •D. You cannot display a chart in stack mode, only a timechart. | show 🗑
|
||||
If no value is specified with the fillnull command, what default value will be used? • A. 0 • B. N/A • C. ג€" • D. NULL | show 🗑
|
||||
What will produce exactly the same results as | chart count over vendor_action by user? | chart count by vendor_action, user | chart count over vendor_action, user | chart count by vendor_action over user | chart count over user by vendor_action | show 🗑
|
||||
What are the two parts of a root event dataset? • A. Fields and variables. • B. Fields and attributes. • C. Constraints and fields. • D. Constraints and lookups. | show 🗑
|
||||
show | 1, because _time is already implied as the x-axis.
🗑
|
||||
A field alias has been created based on an original field. A search without any transforming commands is then executed in Smart Mode. Which field name appears in the results? | show 🗑
|
||||
show | • C. A macro is a reusable search string that may have a flexible time range.
🗑
|
||||
In what order are the following knowledge objects/configurations applied? Field Aliases, Field Extractions, Lookups Field Extractions, Field Aliases, Lookups Field Extractions, Lookups, Field Aliases Lookups, Field Aliases, Field Extractions | show 🗑
|
||||
In which of the following scenarios is an event type more effective than a saved search? | show 🗑
|
||||
show | c. timechart
🗑
|
||||
show | b. Field aliases are applied before lookups.
c. Field aliases can be applied to lookups.
d. The original field is not replaced by the field alias.
🗑
|
||||
show | b. Link
🗑
|
Review the information in the table. When you are ready to quiz yourself you can hide individual columns or the entire table. Then you can click on the empty cells to reveal the answer. Try to recall what will be displayed before clicking the empty cell.
To hide a column, click on the column name.
To hide the entire table, click on the "Hide All" button.
You may also shuffle the rows of the table by clicking on the "Shuffle" button.
Or sort by any of the columns using the down arrow next to any column heading.
If you know all the data on any row, you can temporarily remove it by tapping the trash can to the right of the row.
To hide a column, click on the column name.
To hide the entire table, click on the "Hide All" button.
You may also shuffle the rows of the table by clicking on the "Shuffle" button.
Or sort by any of the columns using the down arrow next to any column heading.
If you know all the data on any row, you can temporarily remove it by tapping the trash can to the right of the row.
Embed Code - If you would like this activity on your web page, copy the script below and paste it into your web page.
Normal Size Small Size show me how
Normal Size Small Size show me how
Created by:
rruiz57