exam questions

Exam SPLK-1004 All Questions

View all questions & answers for the SPLK-1004 exam

Exam SPLK-1004 topic 1 question 18 discussion

Actual exam question from Splunk's SPLK-1004
Question #: 18
Topic #: 1
[All SPLK-1004 Questions]

What does the query | makeresults generate?

  • A. A timestamp
  • B. A results field
  • C. An error message
  • D. The results of the previously run search
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ykamalharsha
1 month, 2 weeks ago
Selected Answer: A
The makeresults command generates a result with the _time field set to the current time. https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Makeresults
upvoted 1 times
...
Vidomina
7 months, 3 weeks ago
Selected Answer: A
| makeresults alone generates "_time" only
upvoted 1 times
...
emlch
7 months, 3 weeks ago
Selected Answer: A
Makeresults generates a timestamp so you can create an event with that timestamp, mainly for purposes (i.e. testing an alert). Generates a single event in memory with only the _time field. You can add event fields using eval. Must be the first command in search succeeding a pipe
upvoted 1 times
...
Eddie_exam
8 months, 1 week ago
It generates the specified number of search results in temporary memory. With a single field, _time.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago