nerdexam
Splunk

SPLK-1002 · Question #141

Which of the following searches show a valid use of a macro? (Choose all that apply.)

The correct answer is A. index=main source=mySource oldField=* |'makeMyField(oldField)'| table _time newField C. index=main source=mySource oldField=* | eval newField='makeMyField(oldField)'| table _time. The searches A and C show a valid use of a macro. A macro is a reusable piece of SPL code that can be called by using single quotes ('). A macro can take arguments, which are passed inside parentheses after the macro name. For example, makeMyField(oldField)' calls a macro named…

Creating and Using Macros

Question

Which of the following searches show a valid use of a macro? (Choose all that apply.)

Options

  • Aindex=main source=mySource oldField=* |'makeMyField(oldField)'| table _time newField
  • Bindex=main source=mySource oldField=* | stats if(`makeMyField(oldField)') | table _time newField
  • Cindex=main source=mySource oldField=* | eval newField='makeMyField(oldField)'| table _time
  • Dindex=main source=mySource oldField=* | "'newField(`makeMyField(oldField)')'" | table _time

How the community answered

(58 responses)
  • A
    83% (48)
  • B
    10% (6)
  • D
    7% (4)

Explanation

The searches A and C show a valid use of a macro. A macro is a reusable piece of SPL code that can be called by using single quotes ('). A macro can take arguments, which are passed inside parentheses after the macro name. For example, makeMyField(oldField)' calls a macro named makeMyField with an argument oldField. The searches B and D are not valid because they use double quotes ("") instead of single quotes (`').

Topics

#Splunk macros#Macro syntax#Eval command#Search commands

Community Discussion

No community discussion yet for this question.

Full SPLK-1002 Practice