nerdexam
Splunk

SPLK-1002 · Question #251

Which of the following can be saved as an event type?

The correct answer is A. index=server_496 sourcetype=BETA_534 code=610. Event types in Splunk can only be saved from searches that are purely event-retrieving - meaning no pipe characters (|), no transforming commands (like stats, chart, table), no subsearches, and no time range modifiers. Option A is a simple, pipe-free search and qualifies…

Creating Tags and Event Types

Question

Which of the following can be saved as an event type?

Options

  • Aindex=server_496 sourcetype=BETA_534 code=610
  • Bindex=server_49c sourcetype=BETA_534 code=610 | stats count by code
  • Cindex=server_496 sourcetype=BETA_534 code=610 | where code > 200
  • Dindex=server_496 sourcetype=BETA_534 code=610 [| inputlookup append=t servercode.csv]

How the community answered

(36 responses)
  • A
    92% (33)
  • B
    3% (1)
  • C
    6% (2)

Explanation

Event types in Splunk can only be saved from searches that are purely event-retrieving - meaning no pipe characters (|), no transforming commands (like stats, chart, table), no subsearches, and no time range modifiers. Option A is a simple, pipe-free search and qualifies. Option B uses | stats (a transforming command), Option C uses | where (a pipe command), and Option D contains a subsearch ([| inputlookup ...]). All of B, C, and D are disqualified because event types cannot include pipes or subsearches.

Topics

#Event Types#SPL#Search Fundamentals#Raw Events

Community Discussion

No community discussion yet for this question.

Full SPLK-1002 Practice