nerdexam
Splunk

SPLK-1002 · Question #243

What does the transaction command do?

The correct answer is B. Creates a single event from a group of events. The transaction command in Splunk groups related events together and combines them into a single event (B). It is commonly used to correlate events that share a common field value (like a session ID or username) and optionally bounded by time or pause thresholds. The resulting…

Correlating Events

Question

What does the transaction command do?

Options

  • AGroups a set of transactions based on time.
  • BCreates a single event from a group of events.
  • CSeparates two events based on one or more values.
  • DReturns the number of credit card transactions found in the event logs.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    94% (30)
  • D
    3% (1)

Explanation

The transaction command in Splunk groups related events together and combines them into a single event (B). It is commonly used to correlate events that share a common field value (like a session ID or username) and optionally bounded by time or pause thresholds. The resulting single event contains all the raw text of the grouped events, their combined duration, and an event count. It does not separate events (C), is not limited to credit card data (D), and while time plays a role in its constraints, it does not simply group by time alone (A).

Topics

#transaction command#event correlation#event grouping

Community Discussion

No community discussion yet for this question.

Full SPLK-1002 Practice