nerdexam
Splunk

SPLK-1002 · Question #29

To identify all of the contributing events within a transaction that contains at least one REJECT event, which syntax is correct?

The correct answer is B. Index-main | transaction sessionid | search REJECT. Option B (index=main | transaction sessionid | search REJECT) is the correct two-step approach: first, transaction sessionid groups all related events sharing the same sessionid into complete transactions; then search REJECT filters to return only those entire transactions that…

Correlating Events

Question

To identify all of the contributing events within a transaction that contains at least one REJECT event, which syntax is correct?

Options

  • AIndex-main | REJECT trans sessionid
  • BIndex-main | transaction sessionid | search REJECT
  • CIndex=main | transaction sessionid | whose transaction=reject
  • DIndex=main | transaction sessionid | where transaction=reject''

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    84% (32)
  • C
    3% (1)
  • D
    11% (4)

Explanation

Option B (index=main | transaction sessionid | search REJECT) is the correct two-step approach: first, transaction sessionid groups all related events sharing the same sessionid into complete transactions; then search REJECT filters to return only those entire transactions that contain the word REJECT - preserving all contributing events within matching transactions, not just the REJECT event itself. (A) has invalid SPL syntax with 'REJECT trans'. (C) uses a non-existent 'whose' keyword. (D) uses where transaction=reject which is not valid syntax for this use case - where is used for field comparisons, not for searching within transaction text.

Topics

#transaction command#event correlation#filtering#SPL

Community Discussion

No community discussion yet for this question.

Full SPLK-1002 Practice