SPLK-1002 Transactions and Event Correlation • Set 10
SPLK-1002 Transactions and Event Correlation Practice Test 10 — 15 questions with explanations. Free, no signup.
A network operations team monitors firewall logs using Splunk. They need to group events from the same TCP session, identified by 'src_ip', 'dst_ip', and 'src_port'. The logs contain events for 'session_start', 'data_transfer', and 'session_end' actions. They currently use `transaction src_ip dst_ip src_port startswith=action=session_start endswith=action=session_end`. However, many transactions are incomplete because some sessions do not have a 'session_end' event due to firewall timeouts. The team wants to include these incomplete sessions as well, but still group them around a start event. What should they modify?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.