For choropleth maps,splunk ships with the following KMZ files (select all that apply)
In most large Splunk environments, what is the most efficient command that can be used to group events by fields/
Which of the following statements would help a user choose between the transaction and stats commands?
Given the following eval statement:
... | eval field1 = if(isnotnull(field1),field1,0), field2 = if(isnull(field2), "NO-VALUE", field2)
Which of the following is the equivalent using fillnull?
Clicking a SEGMENT on a chart, ________.
What is the Splunk Common Information Model (CIM)?
Which of the following statements is true about the root dataset of a data model?
A user wants to create a workflow action that will retrieve a specific field value from an event and run a search in a new browser window
in the user's Splunk instance. What kind of workflow action should they create?
When a search returns __________, you can view the results as a list.
A data model consists of which three types of datasets?