exam questions

Exam SPLK-1002 All Questions

View all questions & answers for the SPLK-1002 exam

Exam SPLK-1002 topic 1 question 65 discussion

Actual exam question from Splunk's SPLK-1002
Question #: 65
Topic #: 1
[All SPLK-1002 Questions]

Which of the following searches would create a graph similar to the one below?

  • A. index=_internal sourcetype=SavedSplunker | fields sourcetype, status | transaction status maxspan=1d | stats count by status
  • B. index=_internal sourcetype=SavedSplunker | fields sourcetype, status | transaction status maxspan=1d | chart count OVER status by _time
  • C. index=_internal sourcetype=SavedSplunker | fields sourcetype, status | transaction status maxspan=1d | timechart count by status
  • D. None of these searches would generate a similar graph.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
None of these functions related to the graph in exhibit. All of these functions have maxspan=ld which is not a valid argument.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
New_user
Highly Voted 3 years, 5 months ago
Answer is D. The argument maxspan=1d will join events to one transaction by status per day. You would see the curve lines on graph if answer C is right, cause graph values are shown with span=12h
upvoted 14 times
rafiki31
2 years, 8 months ago
The graphs values are well shown with 24h span, it's just the x axis showing the 12h intervals but there is no point in between. C.
upvoted 3 times
...
TestingAccount900
2 years, 3 months ago
Correct, but your reasoning is abit off, maxspan will set the maximum point between the earliest and latest transaction, so 1D would be the maximum limit between the first/last, which is obviously not true in the graph.
upvoted 2 times
...
...
paro2
Highly Voted 3 years, 7 months ago
C is the right answer.
upvoted 7 times
...
S_E_A_N
Most Recent 2 weeks, 5 days ago
Should be C, because the question is asking for "similar," not exact, and C is the classiest
upvoted 1 times
...
tatdatpham
4 months ago
C or D
upvoted 1 times
voiddraco
3 months, 2 weeks ago
C is the answer
upvoted 1 times
...
...
Alexi2415
10 months, 2 weeks ago
I tested it and C gives similar result. what I tried : index=web sourcetype=access_combined | fields sourcetype, status | transaction status maxspan=1d | timechart count by status
upvoted 1 times
...
StevenBzh
1 year, 2 months ago
Selected Answer: C
C is the correct answer
upvoted 1 times
...
jsk46
1 year, 3 months ago
what is the correct answ C or D?
upvoted 1 times
...
kirtak
1 year, 8 months ago
Selected Answer: C
C works, tested with different sourcetype that has the same status field with skipped and success index=_internal sourcetype=scheduler | fields sourcetype, status | transaction status maxspan=1d | timechart count by status
upvoted 1 times
Hurshbabe
1 year, 3 months ago
Timechart must have _time on the x-axis. this is definitely not tirmechart
upvoted 2 times
Asheel1
10 months, 2 weeks ago
@Hurshbabe what is the x-axis in your opinion? the vertical or horizontal line? Because i see time on the x-axis.
upvoted 1 times
...
...
...
codemk
2 years ago
https://docs.splunk.com/Documentation/Splunk/9.0.2/SearchReference/Transaction maxspan Syntax: maxspan=<int>[s | m | h | d] Description: Specifies the maximum length of time in seconds, minutes, hours, or days that the events can span. The events in the transaction must span less than integer specified for maxspan. Events that exceed the maxspan limit are treated as part of a separate transaction. If the value is negative, the maxspan constraint is disabled and there is no limit. Default: -1 (no limit)
upvoted 1 times
SolventCourseisSCAM
1 year, 11 months ago
answer is D?
upvoted 1 times
...
...
Hudda
3 years, 5 months ago
could you pls confirm the final answer friends?
upvoted 2 times
...
hellonair
3 years, 6 months ago
Tested . C appears to be correct
upvoted 7 times
...
Shafiqul
3 years, 7 months ago
While I was on playing around with the Splunk training data (sourcetype=access_combined_wcookie), seems C produces the same type linechart graph (assuming the status field has only 2 values in the events skipped and success)..
upvoted 2 times
...
RoGr
3 years, 8 months ago
I would go for answer D: (fields sourcetype, status are not equal to skipped and succes)
upvoted 6 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago