exam questions

Exam SPLK-3003 All Questions

View all questions & answers for the SPLK-3003 exam

Exam SPLK-3003 topic 1 question 65 discussion

Actual exam question from Splunk's SPLK-3003
Question #: 65
Topic #: 1
[All SPLK-3003 Questions]

Consider the search shown below.

What is this search's intended function?

  • A. To return all the web_log events from the web index that occur two hours before and after the most recent high severity, denied event found in the firewall index.
  • B. To find all the denied, high severity events in the firewall index, and use those events to further search for lateral movement within the web index.
  • C. To return all the web_log events from the web index that occur two hours before and after all high severity, denied events found in the firewall index.
  • D. To search the firewall index for web logs that have been denied and are of high severity.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Giodada
Highly Voted 2 years, 10 months ago
A is correct because there is a stats command inside the subsearch
upvoted 7 times
...
frappe
Highly Voted 1 year, 2 months ago
Selected Answer: A
A mentions most recent, and the search has stats latest(_time) in its subsearch
upvoted 5 times
...
jcisco123
Most Recent 8 months, 2 weeks ago
The correct answer is A. The search is intended to return all the web_log events from the web index that occur two hours before and after the most recent high severity, denied event found in the firewall index. The intended function of this search is to return all the web_log events from the web index that occur two hours before and after the most recent high severity, denied event found in the firewall index. The subsearch within square brackets is searching the firewall index for the most recent high severity, denied event, and using the status command to get the latest time for that event. The eval command is then used to create earliest and latest fields for the web_log search, based on the time of the most recent denied event. The fields command at the end is used to limit the fields returned to earliest and latest.
upvoted 1 times
...
nutsu
2 years, 1 month ago
A, because used stats lastest time
upvoted 1 times
...
sunil299
2 years, 2 months ago
C appear correct to me, as latest has +2 hour. so 2 hours before and after events
upvoted 1 times
k3115807
1 year, 12 months ago
C is wrong, because stats latest(_time). This means current time, not all time
upvoted 1 times
...
...
Nemo72
2 years, 9 months ago
A is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago