New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

SPLK-1001 Splunk Exam Lab Questions

Page: 4 / 18
Total 244 questions

Splunk Core Certified User Questions and Answers

Question 13

You can use the following options to specify start and end time for the query range:

Options:

A.

earliest=

B.

latest=

C.

beginning=

D.

ending=

E.

All the above

F.

Only 3rd and 4th

Question 14

Which search string returns a filed containing the number of matching events and names that field Event Count?

Options:

A.

index=security failure | stats sum as “Event Count”

B.

index=security failure | stats count as “Event Count”

C.

index=security failure | stats count by “Event Count”

D.

index=security failure | stats dc(count) as “Event Count”

Question 15

You can on-board data to Splunk using following means (Choose four.):

Options:

A.

Props

B.

CLI

C.

Splunk Web

D.

savedsearches.conf

E.

Splunk apps and add-ons

F.

indexes.conf

G.

inputs.conf

Question 16

Log filtering/parsing can be done from _____________.

Options:

A.

Index Forwarders (IF)

B.

Universal Forwarders (UF)

C.

Super Forwarder (SF)

D.

Heavy Forwarders (HF)

Page: 4 / 18
Total 244 questions