SPLK-1002 Advanced Visualization and Lookups • Set 2
SPLK-1002 Advanced Visualization and Lookups Practice Test 2 — 15 questions with explanations. Free, no signup.
A large e-commerce company has a Splunk environment ingesting web server logs from multiple data centers. The security team needs to visualize failed login attempts over time, grouped by geographic region. They have a lookup file geo_region.csv that maps IP addresses to regions. The lookup is defined in transforms.conf with max_matches=0 (all matches) and is used as an automatic lookup in props.conf for the sourcetype 'web_access'. The search returns events with multiple region values per IP (because max_matches=0). The team wants a single region per event for accurate counting. They also need to reduce the number of events processed by filtering only login failures (status=401). Which approach should be taken?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.