exam questions

Exam SPLK-1002 All Questions

View all questions & answers for the SPLK-1002 exam

Exam SPLK-1002 topic 1 question 10 discussion

Actual exam question from Splunk's SPLK-1002
Question #: 10
Topic #: 1
[All SPLK-1002 Questions]

Which of the following statements would help a user choose between the transaction and stats commands?

  • A. stats can only group events using IP addresses.
  • B. The transaction command is faster and more efficient.
  • C. There is a 1000 event limitation with the transaction command.
  • D. Use stats when the events need to be viewed as a single correlated event.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Lalithadevi
Highly Voted 3 years, 3 months ago
C is correct. Refer Page 134 Fundamentals2
upvoted 13 times
othman
3 years, 1 month ago
Pg. 135 not 134. By default, there’s a limit of 1,000 events per transaction but the admin can change it.
upvoted 5 times
...
...
awsgeeky
Most Recent 4 weeks ago
Selected Answer: C
C is correct even according to Udemy course
upvoted 1 times
...
tineboy46
5 months, 2 weeks ago
C is the correct answer.
upvoted 2 times
...
kruasan
10 months, 3 weeks ago
Selected Answer: C
The transaction command in Splunk is used to group events together based on common field values, time periods, or other criteria. It's particularly useful when you have log data with related events that need to be treated as a single transaction for analysis or reporting purposes.
upvoted 2 times
...
BrynnML
1 year ago
C is correct. D isn't correct because you would use the "transaction" command to group events as a single correlated event NOT the "stats" command as stated in the question
upvoted 4 times
...
HereToLearny
1 year, 1 month ago
Selected Answer: D
The correct answer is D - Splunk documentation reference https://docs.splunk.com/Documentation/SplunkCloud/latest/Search/Abouttransactions
upvoted 1 times
...
Jimmy123
1 year, 1 month ago
Selected Answer: D
The correct answer is D. Use stats when the events need to be viewed as a single correlated event. The transaction command is used to group events together based on common field values. It can also use more complex constraints such as the total period of the transaction, delays between events within the transaction, and required beginning and ending events. The stats command is used to calculate statistics on events grouped by one or more fields. It does not retain the raw event and other field values from the original event. The transaction command is slower than the stats command, but it is more flexible. It can be used to group events together based on more complex criteria. The stats command is faster, but it is less flexible. It can only group events together based on field values. The transaction command is limited to 1000 events. The stats command has no limit on the number of events that it can group together. If you need to view the events as a single correlated event, you should use the transaction command. If you need to calculate statistics on the events, you should use the stats command.
upvoted 3 times
BrynnML
1 year ago
would the answer not be C as in the text you reference it says "use transaction for a single correlated event" and D states using "stats" for single correlated event..
upvoted 3 times
...
...
AlexSOC
1 year, 3 months ago
Selected Answer: C
C is correct.
upvoted 3 times
...
raizen11
1 year, 3 months ago
Ans is C D statement cab be corrected by replacing stats with trasnaction.... Use Transaction when the events need to be viewed as a single correlated event
upvoted 1 times
...
yaman778
1 year, 5 months ago
Selected Answer: D
As other people’s comments the limitation of events quantity is changeable by admin. I think D is much better than C, But I didn’t find evidence. We have 2 specific cases refer to use transaction better. 1.unique ID alone is not sufficient to discriminate between 2 transactions. 2. When it is desirable to see the raw text of the events combined rather than analysis on constituent fields of events.
upvoted 1 times
...
MxQ3
2 years, 1 month ago
Limit of 1,000 events per transaciton to no limits when using stats.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago