Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

Splunk SPLK-1001 Splunk Core Certified User Exam Practice Test

Page: 1 / 23
Total 226 questions

Splunk Core Certified User Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$40.25  $114.99

PDF Study Guide

  • Product Type: PDF Study Guide
$35  $99.99
Question 1

Which of the following can be used as wildcard search in Splunk?

Options:

A.

=

B.

>

C.

!

D.

*

Question 2

Which statement is true about the top command?

Options:

A.

It returns the top 10 results

B.

It displays the output in table format

C.

It returns the count and percent columns per row

D.

All of the above

Question 3

What options do you get after selecting timeline? (Choose four.)

Options:

A.

Zoom to selection

B.

Format Timeline

C.

Deselect

D.

Delete

E.

Zoom Out

Question 4

Which statement is true about Splunk alerts?

Options:

A.

Alerts are based on searches that are either run on a scheduled interval or in real-time.

B.

Alerts are based on searches and when triggered will only send an email notification.

C.

Alerts are based on searches and require cron to run on scheduled interval.

D.

Alerts are based on searches that are run exclusively as real-time.

Question 5

It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.

Options:

A.

True

B.

False

Question 6

Which of the following is an option after clicking an item in search results?

Options:

A.

Saving the item to a report

B.

Adding the item to the search.

C.

Adding the item to a dashboard

D.

Saving the search to a JSON file.

Question 7

Which component of Splunk let us write SPL query to find the required data?

Options:

A.

Forwarders

B.

Indexer

C.

Heavy Forwarders

D.

Search head

Question 8

Which of the following statements describes a search job?

Options:

A.

Once a search job begins, it cannot be stopped

B.

A search job can only be paused when less than 50% of events are returned

C.

A search job can only be stopped when less than 50% of events are returned

D.

Once a search job begins, it can be stopped or paused at any point in time

Question 9

There are three different search modes in Splunk (Choose three.):

Options:

A.

Automatic

B.

Smart

C.

Fast

D.

Verbose

Question 10

In the Splunk interface, the list of alerts can be filtered based on which characteristics?

Options:

A.

App, Owner, Severity, and Type

B.

App, Owner, Priority, and Status

C.

App, Dashboard, Severity, and Type

D.

App, Time Window, Type, and Severity

Question 11

Lookups allow you to overwrite your raw event.

Options:

A.

True

B.

False

Question 12

Which of the following is true about user account settings and preferences?

Options:

A.

Search & Reporting is the only app that can be set as the default application.

B.

Full names can only be changed by accounts with a Power User or Admin role.

C.

Time zones are automatically updated based on the setting of the computer accessing Splunk.

D.

Full name, time zone, and default app can be defined by clicking the login name in the Splunk bar.

Question 13

Which of the statements are correct? (Choose three.)

Options:

A.

Zoom to selection: Narrows the time range and re-executes the search.

B.

Zoom to selection: Narrows the time range and doesn't re-executes the search.

C.

Format Timeline: Hides or shows the timeline in different views.

D.

Zoom-Out: Expands the time focus and doesn't re-executes the search.

E.

Zoom-out: Expands the time focus and re-executes the search.

Question 14

How can another user gain access to a saved report?

Options:

A.

The owner of the report can edit permissions from the Edit dropdown

B.

Only users with an Admin or Power User role can access other users' reports

C.

Anyone can access any reports marked as public within a shared Splunk deployment

D.

The owner of the report must clone the original report and save it to their user account

Question 15

This function of the stats command allows you to return the sample standard deviation of a field.

Options:

A.

stdev

B.

dev

C.

count deviation

D.

by standarddev

Question 16

What is a quick, comprehensive way to learn what data is present in a Splunk deployment?

Options:

A.

Review Splunk reports

B.

Run ./splunk show

C.

Click Data Summary in Splunk Web

D.

Search index=* sourcetype=* host=*

Question 17

Splunk Components:

Which of the following are responsible for parsing incoming data and storing data on disc?

Options:

A.

forwarders

B.

indexers

C.

search heads

Question 18

What does the following specified time range do?

earliest=-72h@h latest=@d

Options:

A.

Look back 3 days ago and prior

B.

Look back 72 hours up to one day ago

C.

Look back 72 hours, up to the end of today

D.

Look back from 3 days ago up to the beginning of today

Question 19

Three basic components of Splunk are (Choose three.):

Options:

A.

Forwarders

B.

Deployment Server

C.

Indexer

D.

Knowledge Objects

E.

Index

F.

Search Head

Question 20

When is the pipe character, I, used in search strings?

Options:

A.

Before clauses. For example: stats sum(bytes) | by host

B.

Before commands. For example: | stats sum(bytes) by host

C.

Before arguments. For example: stats sum| (bytes) by host

D.

Before functions. For example: stats |sum(bytes) by host

Question 21

Which of the following Splunk components typically resides on the machines where data originates?

Options:

A.

Indexer

B.

Forwarder

C.

Search head

D.

Deployment server

Question 22

A collection of items containing things such as data inputs, UI elements, and knowledge objects is known as what?

Options:

A.

An app

B.

JSON

C.

A role

D.

An enhanced solution

Question 23

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

Options:

A.

host

B.

index

C.

source

D.

sourcetype

Question 24

Beginning parentheses is automatically highlighted to guide you on the presence of complimenting

parentheses.

Options:

A.

No

B.

Yes

Question 25

Which of the following file types is an option for exporting Splunk search results?

Options:

A.

PDF

B.

JSON

C.

XLS

D.

RTF

Question 26

What is one benefit of creating dashboard panels from reports?

Options:

A.

Any newly created dashboard will include that report.

B.

There are no benefits to creating dashboard panels from reports.

C.

It makes the dashboard more efficient because it only has to run one search string.

D.

Any change to the underlying report will affect every dashboard that utilizes that report.

Question 27

Which of the following index searches would provide the most efficient search performance?

Options:

A.

index=*

B.

index=web OR index=s*

C.

(index=web OR index=sales)

D.

*index=sales AND index=web*

Question 28

Will the queries following below get the same result?

1. index=log sourcetype=error_log status !=100

2. index=log sourcetype=error_log NOT status =100

Options:

A.

Yes

B.

No

Question 29

Use this command to use lookup fields in a search and see the lookup fields in the field sidebar.

Options:

A.

inputlookup

B.

lookup

Question 30

When viewing results of a search job from the Activity menu, which of the following is displayed?

Options:

A.

New events based on the current time range picker

B.

The same events based on the current time range picker

C.

The same events from when the original search was executed

D.

New events in addition to the same events from the original search

Question 31

The stats command will create a _____________ by default.

Options:

A.

Table

B.

Report

C.

Pie chart

Question 32

You can use the following options to specify start and end time for the query range:

Options:

A.

earliest=

B.

latest=

C.

beginning=

D.

ending=

E.

All the above

F.

Only 3rd and 4th

Question 33

When placed early in a search, which command is most effective at reducing search execution time?

Options:

A.

dedup

B.

rename

C.

sort -

D.

fields +

Page: 1 / 23
Total 226 questions