Splunk Core Power User Exam
Questions and Answers 100% Pass
Selected fields are displayed ________ each event in the results.
a. below
b. interesting fields
c. other fields
d. above - ✔✔a. below
Search terms are not case sensitive. (T/F) - ✔✔True
These two searches will NOT return the same results.
SEARCH 1:login failure SEARCH 2: "login failure" (T/F) - ✔✔True
A space is implied ______________ in a search string.
a. OR
b. AND
c. ()
d. NOT - ✔✔b. AND
,©JOSHCLAY 2024/2025. YEAR PUBLISHED 2024.
You can not specify a relative time range, such as 45 seconds ago, for a
search (T/F) - ✔✔False
To use field value data from an event in a Workflow Action, we need to:
a. Create tags for the fields.
b. Select the GET method.
c. Wrap the field in dollar signs. - ✔✔c. Wrap the field in dollar signs.
This Workflow Action type sends field values to external resources.
a. POST
b. GET
c. Search - ✔✔a. POST
Workflow Actions can only be applied to a single field.
FALSE
TRUE - ✔✔False
Hidden fields in a data model:
, ©JOSHCLAY 2024/2025. YEAR PUBLISHED 2024.
a. will not be displayed to a Pivot user, but can be used to define other
datasets
b. will not be displayed in the dataset editor
c. will be displayed to a Pivot user that has permissions to the field - ✔✔a.
will not be displayed to a Pivot user, but can be used to define other
datasets
_____ datasets can be added to a root dataset to narrow down the search.
a. event
b. child
c. parent
d. extracted - ✔✔b. child
Which of these are NOT Data Model dataset types:
a. Searches
b. Events
c. Transactions
d. Lookups - ✔✔d. Lookups
You can normalize data for CIM use: