Splunk
SPLK-5001 · Question #8
SPLK-5001 Question #8: Real Exam Question with Answer & Explanation
Sign in or unlock SPLK-5001 to reveal the answer and full explanation for question #8. The question stem and answer options stay visible for context.
Question
Which of the following is a correct Splunk search that will return results in the most performant way?
Options
- Aindex=foo host=i-478619733 | stats range(_time) as duration by src_ip | bin duration span=5min |
- B| stats range(_time) as duration by src_ip | index=foo host=i-478619733 | bin duration span=5min
- Cindex=foo host=i-478619733 | transaction src_ip |stats count by host
- Dindex=foo | transaction src_ip |stats count by host | search host=i-478619733
Unlock SPLK-5001 to see the answer
You've previewed enough free SPLK-5001 questions. Unlock SPLK-5001 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.