Courseiva
Transactions and Event CorrelationmediumMultiple SelectObjective-mapped

SPLK-1002 Transactions and Event Correlation Practice Question

Which TWO fields are automatically created by the transaction command? (Select exactly 2 correct answers.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

_endtime

The transaction command adds _starttime and _endtime fields to each event in the transaction. It also adds duration and eventcount, but those are not listed as options. _time and maxpause are not created by transaction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • total_events

    Why it's wrong here

    The field is eventcount, not total_events.

  • _endtime

    Why this is correct

    Correct: transaction adds _endtime.

  • _starttime

    Why this is correct

    Correct: transaction adds _starttime.

  • _time

    Why it's wrong here

    _time is the original event timestamp, not added by transaction.

  • maxpause

    Why it's wrong here

    maxpause is a parameter, not an added field.

About these practice questions

One of 475 original SPLK-1002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SPLK-1002 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1002 exam.