Using Transforming Commands for Visualizations for Splunk Core Certified Power User
This page covers the Using Transforming Commands for Visualizations domain of the Splunk Core Certified Power User certification. Master Cybersecurity offers 19 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
When using `| timechart by host`, which field is represented in the x-axis?- A. date
- B. host
- C. time
- D. _time
Explanation
The correct answer is: D. _time.
The timechart command always plots time on the x-axis, and the field carrying it is _time, the internal timestamp Splunk assigns to every event at index time. That is what makes timechart distinct from chart: the x-axis is fixed rather than chosen, so the by clause can only supply the series that split the measured values. In this search host becomes those series, producing one line or column group per host, but host never occupies the x-axis. The field named time is not what Splunk uses, since the underscore prefix marks _time as an internal field and a plain time field would exist only if the data happened to contain one, carrying no special meaning. Likewise date is not an internal Splunk field, though date_hour and similar fields may be extracted from some data. Because _time is required, timechart fails on result sets where it has been dropped, for instance after a stats that did not retain it.
Question 2
How does a user display a chart in stack mode?- A. By using the stack command.
- B. By turning on the Use Trellis Layout option.
- C. By changing Stack Mode in the Format menu.
- D. You cannot display a chart in stack mode, only a timechart.
Explanation
The correct answer is: C. By changing Stack Mode in the Format menu..
Stacking is a formatting choice rather than a search operation, so it is applied through the Format menu on the visualization, where the Stack Mode setting offers unstacked, stacked, and stacked 100 percent options. Because it changes only how the already-computed series are drawn, you can switch between modes without rerunning the search. There is no stack command in SPL, so nothing in the search string controls this. The Trellis layout option does something different, splitting the visualization into a grid of small multiples with one panel per value of a chosen field, which separates the series rather than stacking them on shared axes. It is also untrue that stacking is limited to timechart output, since any chart with multiple series can be stacked, including results from chart and from stats with a split-by field. What stacking genuinely requires is more than one series, so a single-series result shows no visible difference.
Question 3
What other syntax will produce exactly the same results as `| chart count over vendor_action by user`?- A. | chart count by vendor_action, user
- B. | chart count over vendor_action, user
- C. | chart count by vendor_action over user
- D. | chart count over user by vendor_action
Explanation
The correct answer is: A. | chart count by vendor_action, user.
With the chart command, over and by name the two dimensions of the resulting table: over sets the field that becomes the row axis, and by sets the field whose values become the columns. Supplying two fields to a single by clause is the equivalent shorthand, where the first field takes the row axis and the second supplies the columns, so by vendor_action, user produces exactly what over vendor_action by user produces. Using over with two comma-separated fields is invalid, because over accepts only one field. Reversing the clauses to put by before over is not valid syntax either, since over must precede by when both appear. Swapping the field positions changes the result rather than preserving it, because over user by vendor_action puts users on the row axis and vendor actions in the columns, which is the transpose of the original table rather than the same output.
Question 4
When using timechart, how many fields can be listed after a by clause?- A. 0, because timechart doesn't support using a by clause.
- B. 1, because _time is already implied as the x-axis.
- C. 2, because one field would represent the x-axis and the other would represent the y-axis.
- D. There is no limit specific to timechart.
Explanation
The correct answer is: B. 1, because _time is already implied as the x-axis..
timechart accepts exactly one field in its by clause, because the x-axis is already committed to _time and the by clause supplies only the series that split the measured values. Each distinct value of that one field becomes a column in the results table and a separate line or band in the visualization. Allowing two would require a third dimension the chart has no room for, which is precisely why the restriction exists and why chart, whose axes are both free, is the command to reach for when two split dimensions are needed. Saying timechart does not support a by clause is wrong, since splitting by a field is one of its most common uses. Claiming two fields are allowed so that one can be the x-axis misunderstands the command, as the x-axis is never taken from the by clause. There is a real limit specific to timechart, so the option denying any limit is incorrect.
Question 5
What does the following search do? index=corndog type=mysterymeat action=eaten | stats count as corndog_count by user- A. Creates a table of the total count of users and split by corndogs.
- B. Creates a table of the total count of mysterymeat corndogs split by user.
- C. Creates a table with the count of all types of corndogs eaten split by user.
- D. Creates a table that groups the total number of users by vegetarian corndogs.
Explanation
The correct answer is: B. Creates a table of the total count of mysterymeat corndogs split by user..
The search first filters and then aggregates, and reading it in that order gives the answer. The base search restricts events to index=corndog with type=mysterymeat and action=eaten, so only mysterymeat corndogs that were eaten survive to the next stage. The stats count as corndog_count by user clause then counts those surviving events and splits the count by user, producing one row per user with a corndog_count column. That makes the output a count of mysterymeat corndogs broken out by user. Counting users split by corndogs inverts the roles, since the by clause determines the split and user is what appears there while the count is the measure. Describing it as all types of corndogs ignores the type=mysterymeat filter, which removes every other type before the count runs. Nothing in the search references a vegetarian type or groups users by one, so that option describes a search never written.
Other Splunk Core Certified Power User domains
- Correlating Events (24 questions)
- Creating and Managing Fields (21 questions)
- Creating and Using Macros (20 questions)
- Creating and Using Workflow Actions (25 questions)
- Creating Data Models (27 questions)
- Creating Field Aliases and Calculated Fields (22 questions)
- Creating Tags and Event Types (21 questions)
- Filtering and Formatting Results (27 questions)
- Using the Common Information Model (CIM) (17 questions)