exam questions

Exam SPLK-1002 All Questions

View all questions & answers for the SPLK-1002 exam

Exam SPLK-1002 topic 1 question 96 discussion

Actual exam question from Splunk's SPLK-1002
Question #: 96
Topic #: 1
[All SPLK-1002 Questions]

Which of the following statements describe the search below? (Choose all that apply.) index=main | transaction clientip host maxspan=30s maxpause=5s

  • A. Events in the transaction occurred within 5 seconds.
  • B. It groups events that share the same clientip and host.
  • C. The first and last events are no more than 5 seconds apart.
  • D. The first and last events are no more than 30 seconds apart
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ArDeKu
Highly Voted 3 years, 7 months ago
A, B, D
upvoted 27 times
thissiteisgreat
3 years, 6 months ago
no. It's A, D. The reference link states the field list captures unique combination of fields not fields with identical value.
upvoted 3 times
Herpflerp
3 years, 3 months ago
Page 126 in F2 PDF "The transaction command creates a single event from a group of events. - The events must share the same value in a specified field" A, B, D
upvoted 9 times
...
paro2
3 years, 5 months ago
I'ts A B D. Go to study.
upvoted 5 times
rafiki31
2 years, 6 months ago
I agree, nevertheless the A is ambiguous, does it means all events within 5 sec or each events separated in less than 5 sec...
upvoted 2 times
foxx99
1 year, 9 months ago
I think ambiguous defines the rest of these questions from the rest of these tests too.
upvoted 2 times
...
...
...
...
...
oat55
Highly Voted 3 years, 6 months ago
It's B,D
upvoted 10 times
...
Sankardevarajan1986
Most Recent 10 months, 1 week ago
Answer ABD reference link https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Transaction
upvoted 1 times
...
Dree_Dogg
1 year, 2 months ago
A,B,D The transaction command creates a single event from a group of events – The events must share the same value in a specified field
upvoted 1 times
...
Dree_Dogg
1 year, 2 months ago
answer = ABD
upvoted 1 times
...
Mntman77
1 year, 4 months ago
B&D - the context for the search is correct. This is an example directly from Splunk: "transaction host cookie maxspan=30s maxpause=5s"
upvoted 2 times
...
Harrysa
1 year, 6 months ago
The correct answer is D. The maxspan option specifies that the first and last events in a transaction can be no more than 30 seconds apart. The maxpause option specifies that if there is a pause between events longer than 5 seconds, a new transaction will be started. Therefore, option D is correct as it describes the maximum time duration allowed for a transaction to occur between its first and last events. Options A and C are incorrect because they refer to a different parameter not mentioned in the Splunk search command. Option B is partially correct, as it describes the fields used to group events together, but it does not describe the time constraints on the transaction itself.
upvoted 2 times
...
tomhola
1 year, 7 months ago
answer is BD - Define a transaction based on Web access events that share the same IP address. The first and last events in the transaction should be no more than thirty seconds apart and each event should not be longer than five seconds apart. https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Transaction#transaction
upvoted 1 times
...
Takaks007
1 year, 10 months ago
Selected Answer: BD
A is wrong: the maxspan defines the maximum pause between 2 consecutive events
upvoted 2 times
...
shergar
2 years ago
Selected Answer: BD
Example is here: https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchReference/Transaction Define a transaction based on Web access events that have a unique combination of host and clientip values. The first and last events in the transaction should be no more than thirty seconds apart and each event should not be longer than five seconds apart. So it would group events in a transaction where IP=1.2.3.4 and hostwww1. IP=1.2.3.4 and host=www2 would be in another transacton (B) A is a trick question or badly formulated. Pause between events within the transactions should be no more than 5s apart. However, the total transaction time can be much longer.
upvoted 2 times
...
nicksss
2 years ago
Selected Answer: BD
B,D are correct. Here is the description of the maxpause command Specifies the maximum length of time in seconds, minutes, hours, or days for the pause between the events in a transaction. If value is negative, the maxpause constraint is disabled and there is no limit. A would only be definitively correct if the transaction had 2 events. If it has more than 2 events then the time between the first and last event are unknown, all we know is no 2 events are more than 5 seconds apart.
upvoted 1 times
...
Dutz
2 years, 7 months ago
A,B, D
upvoted 1 times
...
Dutz
2 years, 7 months ago
It's B,D
upvoted 3 times
...
RoVasq3
2 years, 7 months ago
Selected Answer: AD
I'ts A B D. Go to study.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago