exam questions

Exam SPLK-1002 All Questions

View all questions & answers for the SPLK-1002 exam

Exam SPLK-1002 topic 1 question 180 discussion

Actual exam question from Splunk's SPLK-1002
Question #: 180
Topic #: 1
[All SPLK-1002 Questions]

Brad created a tag called "SpecialProjectX". It is associated with several field/value pairs, such as team=support, location=Austin, and release=Fuji.

What search should Brad run to filter results for SpecialProjectX events related to the Support Team?

  • A. tag!=Fuji,Austin
  • B. tag=SpecialProjectX
  • C. tag::Support=SpecialProjectX
  • D. tag::team-SpecialProjectX
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Sumaiya_Khanom
2 weeks, 2 days ago
Selected Answer: D
In Splunk, you can search for tagged events with a specific tag by specifying the field in the search query. tag::team-SpecialProjectX indicates you are searching for events tagged with the field team that has the value SpecialProjectX. This matches the events tagged for the SpecialProjectX project, specifically those related to the Support Team (team=support). Why not the other options? A. tag!=Fuji,Austin: This would exclude tags with the values Fuji and Austin, but it doesn't narrow down to SpecialProjectX or Support Team. It’s not specific enough for your need. B. tag=SpecialProjectX: While this would filter for all events tagged with SpecialProjectX, it doesn't filter for the Support Team specifically. It gives too broad of a result. C. tag::Support=SpecialProjectX Most Voted: This option doesn't fit the correct Splunk syntax. It's not properly formatted for filtering by tag and field-value pairs.
upvoted 1 times
...
grx42
3 weeks, 5 days ago
Selected Answer: B
Question says search for events, not fields. Correct answer is B.
upvoted 1 times
...
BOSS2107
2 months, 3 weeks ago
Selected Answer: C
Search for specific tag alonside with specifilc field. C is the correct. It is asking for result SpecialProjectX events RELATED TO the Support Team - and there is such field. What search should Brad run to filter results for SpecialProjectX events related to the Support Team?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago