Splunk
SPLK-5001 · Question #118
SPLK-5001 Question #118: Real Exam Question with Answer & Explanation
Sign in or unlock SPLK-5001 to reveal the answer and full explanation for question #118. The question stem and answer options stay visible for context.
Question
As an analyst, tracking unique users is a common occurrence. The Security Operations Center (SOC) manager requested a search with results in a table format to track the cumulative downloads by distinct IP address. Which example calculates the running total of distinct users over time?
Options
- Aeventtype="download" | bin _time span=1d as day | table clientip day
- Beventtype="download" | bin _time span=1d as day | stats values(clientip)
- Ceventtype="download" | bin _time span=1d as day | stats values(clientip)
- Deventtype="download" | bin _time span=1d as day | stats values(clientip)
Unlock SPLK-5001 to see the answer
You've previewed enough free SPLK-5001 questions. Unlock SPLK-5001 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.