
SplunkCore Certified Power User
Domain 3Objective 5
Report on Transactions SPLK-1002 Practice Questions (Page 1)
Part of the Correlating Events domain, which accounts for 15% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
6concepts
15%of the exam
Questions 1–5
- 1
An analyst is using the transaction command and wants to ensure that transactions are not split if there is a pause of up to 2 minutes between events. Which option should they set?
Select an answer first - 2
In the transaction command, what does the startswith option specify?
Select an answer first - 3
A data analyst needs to correlate events by a `job_id` field and also needs to list all the error codes that occurred for each job. The dataset is large, and the analyst is concerned about performance. Which approach is most efficient?
Select an answer first - 4
Which strategy can help optimize the performance of a search that uses the transaction command?
Select an answer first - 5
An analyst is using the transaction command to group events. They notice that some transactions are being discarded because they exceed the maximum number of events. They want to keep these transactions for further analysis but still want to see them in the results. Which option should they add to the transaction command?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.