SPLK-1002 Transactions and Event Correlation • Set 7
SPLK-1002 Transactions and Event Correlation Practice Test 7 — 15 questions with explanations. Free, no signup.
A Splunk admin is troubleshooting a transaction that groups firewall allow and deny events by session ID. The transaction should end when a deny event occurs for that session. Which transaction option should be used to define the end condition?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.