SPLK-1002 Advanced Searching and Statistics • Set 3
SPLK-1002 Advanced Searching and Statistics Practice Test 3 — 15 questions with explanations. Free, no signup.
A Splunk administrator is troubleshooting a search that uses the transaction command to group login and logout events. The search runs but returns no results even though both types of events exist. The events are separated by at most 5 minutes. The current transaction command is:
`index=auth (action=login OR action=logout) | transaction action maxspan=10m maxpause=2s`
What is the most likely cause?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.