SPLK-1002 • Practice Test 19
Free SPLK-1002 practice test — 15 questions with explanations. Set 19. No signup required.
A Splunk Power User maintains a macro named `net_errors` defined with arguments as `sourcetype=$st$ status=error | stats count by host`. Several saved searches call it as `` `net_errors(firewall)` ``. The admin later needs one specific saved search to also break the count down by `src_ip` without altering the macro for everyone else. What is the most appropriate way to accomplish this within Splunk?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.