Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-1002 Topic 8 Question 82 Discussion

Actual exam question for Splunk's SPLK-1002 exam
Question #: 82
Topic #: 8
[All SPLK-1002 Questions]

Consider the following search:

index=web sourcetype=access_corabined

The log shows several events that share the same jsesszonid value (SD462K101O2F267). View the events as a group.

From the following list, which search groups events by jSSESSIONID?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Keena
5 months ago
That's a good point, Mozell. I see why C) could be the correct answer now.
upvoted 0 times
...
Mozell
5 months ago
I think C) is the right answer because it uses 'highlight' to group events by JSESSIONID
upvoted 0 times
...
Carlene
5 months ago
But A) specifically uses 'transaction' to group events, which is what the question is asking for
upvoted 0 times
...
Keena
6 months ago
I disagree, I believe the correct answer is B)
upvoted 0 times
...
Carlene
6 months ago
I think the answer is A)
upvoted 0 times
...
Twana
6 months ago
I think C is the correct answer because it highlights the JSESSIONID and then searches for SD462K101O2F267.
upvoted 0 times
...
Brynn
6 months ago
Because it uses the table command to display the JSESSIONID.
upvoted 0 times
...
Annice
7 months ago
Why do you think B is the correct answer?
upvoted 0 times
...
Brynn
7 months ago
I disagree, I believe the correct answer is B.
upvoted 0 times
...
Annice
7 months ago
I think the answer is A.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77