Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-1002 Topic 9 Question 86 Discussion

Actual exam question for Splunk's SPLK-1002 exam
Question #: 86
Topic #: 9
[All SPLK-1002 Questions]

Consider the following search:

index=web sourcetype=access_combined

The log shows several events that share the same JSESSIONID value (SD470K92802F117). View the events as a group.

From the following list, which search groups events by JSESSIONID?

Show Suggested Answer Hide Answer
Suggested Answer: B

To group events by JSESSIONID, the correct search is index=web sourcetype=access_combined | transaction JSESSIONID | search SD470K92802F117 (Option B). The transaction command groups events that share the same JSESSIONID value, allowing for the analysis of all events associated with a specific session as a single transaction. The subsequent search for SD470K92802F117 filters these grouped transactions to include only those related to the specified session ID.


Contribute your Thoughts:

Luis
6 months ago
That makes sense. I was confused between B and D, though.
upvoted 0 times
...
Orville
6 months ago
Because 'transaction JSESSIONID' is intended to group events.
upvoted 0 times
...
Carlota
6 months ago
Why B?
upvoted 0 times
...
Orville
6 months ago
I think option B is the correct one.
upvoted 0 times
...
Luis
7 months ago
Yeah, I agree. Grouping events by JSESSIONID is a bit confusing.
upvoted 0 times
...
Carlota
7 months ago
This exam question is tricky.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77