Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-1001 Topic 4 Question 107 Discussion

Actual exam question for Splunk's SPLK-1001 exam
Question #: 107
Topic #: 4
[All SPLK-1001 Questions]

Contribute your Thoughts:

Jacinta
5 days ago
Option B looks promising, but 'last=15' might not be what we want here. We need the least common values, not the last 15 values.
upvoted 0 times
...
Santos
15 days ago
I think option A is the correct answer. The 'rare' command will return the least common field values, and 'num=15' will limit the results to the 15 least common values.
upvoted 0 times
...
Abel
16 days ago
Hmm, that makes sense too. I guess it depends on how the search is implemented.
upvoted 0 times
...
Ceola
18 days ago
I disagree, I believe the answer is C) sourcetype=firewall | rare count=15 dest_ip because it explicitly mentions counting the values.
upvoted 0 times
...
Abel
22 days ago
I think the answer is A) sourcetype=firewall | rare num=15 dest_ip because it specifies the number of values to return.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77