SPLK-1002 Exam Question 1

Which of the following data model are included In the Splunk Common Information Model (CIM) add-on?
(select all that apply)
  • SPLK-1002 Exam Question 2

    Which of the following eval command functions is valid?
  • SPLK-1002 Exam Question 3

    A user wants to create a workflow action that will retrieve a specific field value from an event and run a search in a new browser window in the user's Splunk instance. What kind of workflow action should they create?
  • SPLK-1002 Exam Question 4

    For choropleth maps,splunk ships with the following KMZ files (select all that apply)
  • SPLK-1002 Exam Question 5

    Which of the following can be saved as an event type?