Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam SPLK-1002 topic 1 question 10 discussion

Actual exam question from Splunk's SPLK-1002
Question #: 10
Topic #: 1
[All SPLK-1002 Questions]

Which of the following statements would help a user choose between the transaction and stats commands?

  • A. stats can only group events using IP addresses.
  • B. The transaction command is faster and more efficient.
  • C. There is a 1000 event limitation with the transaction command.
  • D. Use stats when the events need to be viewed as a single correlated event.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/Transaction

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Lalithadevi
Highly Voted 3 years, 3 months ago
C is correct. Refer Page 134 Fundamentals2
upvoted 12 times
othman
3 years, 1 month ago
Pg. 135 not 134. By default, there’s a limit of 1,000 events per transaction but the admin can change it.
upvoted 5 times
...
...
xekiha7832
Most Recent 1 week, 1 day ago
**D. Use stats when the events need to be viewed as a single correlated event.** Explanation: - The statement in option D helps a user choose between the transaction and stats commands in Splunk. - **Stats** should be used when events need to be viewed and analyzed as a whole, providing statistical summaries or calculations across events. - **Transaction** should be used when events need to be grouped together based on common characteristics or fields to analyze sequences or chains of events. Options A, B, and C provide incorrect or irrelevant information about the transaction and stats commands in Splunk. < https://shorturl.at/8Wc2o > I used ExamTOPICfor my SPLK exam and it was a good experience. The dumps were mostly accurate, but some questions were outdated.
upvoted 1 times
...
tineboy46
5 months ago
C is the correct answer.
upvoted 1 times
...
kruasan
10 months ago
Selected Answer: C
The transaction command in Splunk is used to group events together based on common field values, time periods, or other criteria. It's particularly useful when you have log data with related events that need to be treated as a single transaction for analysis or reporting purposes.
upvoted 2 times
...
BrynnML
12 months ago
C is correct. D isn't correct because you would use the "transaction" command to group events as a single correlated event NOT the "stats" command as stated in the question
upvoted 4 times
...
HereToLearny
1 year, 1 month ago
Selected Answer: D
The correct answer is D - Splunk documentation reference https://docs.splunk.com/Documentation/SplunkCloud/latest/Search/Abouttransactions
upvoted 1 times
...
Jimmy123
1 year, 1 month ago
Selected Answer: D
The correct answer is D. Use stats when the events need to be viewed as a single correlated event. The transaction command is used to group events together based on common field values. It can also use more complex constraints such as the total period of the transaction, delays between events within the transaction, and required beginning and ending events. The stats command is used to calculate statistics on events grouped by one or more fields. It does not retain the raw event and other field values from the original event. The transaction command is slower than the stats command, but it is more flexible. It can be used to group events together based on more complex criteria. The stats command is faster, but it is less flexible. It can only group events together based on field values. The transaction command is limited to 1000 events. The stats command has no limit on the number of events that it can group together. If you need to view the events as a single correlated event, you should use the transaction command. If you need to calculate statistics on the events, you should use the stats command.
upvoted 2 times
BrynnML
12 months ago
would the answer not be C as in the text you reference it says "use transaction for a single correlated event" and D states using "stats" for single correlated event..
upvoted 2 times
...
...
AlexSOC
1 year, 3 months ago
Selected Answer: C
C is correct.
upvoted 3 times
...
raizen11
1 year, 3 months ago
Ans is C D statement cab be corrected by replacing stats with trasnaction.... Use Transaction when the events need to be viewed as a single correlated event
upvoted 1 times
...
yaman778
1 year, 4 months ago
Selected Answer: D
As other people’s comments the limitation of events quantity is changeable by admin. I think D is much better than C, But I didn’t find evidence. We have 2 specific cases refer to use transaction better. 1.unique ID alone is not sufficient to discriminate between 2 transactions. 2. When it is desirable to see the raw text of the events combined rather than analysis on constituent fields of events.
upvoted 1 times
...
MxQ3
2 years ago
Limit of 1,000 events per transaciton to no limits when using stats.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
ex Want to SAVE BIG on Certification Exam Prep?
close
ex Unlock All Exams with ExamTopics Pro 75% Off
  • arrow Choose From 1000+ Exams
  • arrow Access to 10 Exams per Month
  • arrow PDF Format Available
  • arrow Inline Discussions
  • arrow No Captcha/Robot Checks
Limited Time Offer
Ends in