When looking at a statistics table, what is one way to drill down to see the underlying events?
In the Search and Reporting app, which is a default selected field?
Which of the following is the best way to create a report that shows the last 24 hours of events?
Which of the following describes lookup files?
How to make Interesting field into a selected field?
What is the primary use for the rare command1?
What must be done in order to use a lookup table in Splunk?
Splunk automatically determines the source type for major data types.
It is not possible for a single instance of Splunk to manage the input, parsing and indexing of machine.
You are able to create new Index in Data Input settings.
It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.
Splunk apps are used for following (Choose three.):
You can use the following options to specify start and end time for the query range:
Which search string returns a filed containing the number of matching events and names that field Event Count?
You can on-board data to Splunk using following means (Choose four.):
Log filtering/parsing can be done from _____________.
Assuming a user has the capability to edit reports, which of the following are editable?
How are events displayed after a search is executed?
What is the primary use for the rare command?
Select the correct option that applies to Index time processing (Choose three.).
Three basic components of Splunk are (Choose three.):
Which command automatically returns percent and count columns when executing searches?
What does the stats command do?
Which of the following statements are correct about Search & Reporting App? (Choose three.)
@ Symbol can be used in advanced time unit option.
Splunk Components:
Which of the following are responsible for reducing search results?
Splunk shows data in __________________.
What is the result of the following search?
index=myindex source=c: \mydata. txt NOT error=*
When a Splunk search generates calculated data that appears in the Statistics tab. in what formats can the results be exported?
What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?
Which of the following fields is stored with the events in the index?
What can be included in the All Fields option in the sidebar?
In the fields sidebar, what indicates that a field is numeric?
Select the best options for "search best practices" in Splunk:
(Choose five.)
What is one benefit of creating dashboard panels from reports?
How can search results be kept longer than 7 days?
Portal for Splunk apps can be accessed through
Which is the default app for Splunk Enterprise?
The new data uploaded in Splunk are shown in ________________.
This function of the stats command allows you to return the middle-most value of field X.
Which stats command function provides a count of how many unique values exist for a given field in the result set?
Which search will return the 15 least common field values for the dest_ip field?
Which is a primary function of the timeline located under the search bar?
Which search string only returns events from hostWWW3?
Which search will return only events containing the word “error” and display the results as a table that includes
the fields named action, src, and dest?
Which command is used to validate a lookup file?
When displaying results of a search, which of the following is true about line charts?
Which time range picker configuration would return real-time events for the past 30 seconds?
Which of the following reports is available in the Fields window?
Field values are case sensitive.
In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?
When looking at a dashboard panel that is based on a report, which of the following is true?
Which statement describes field discovery at search time?
Universal forwarder is recommended for forwarding the logs to indexers.
Zoom Out and Zoom to Selection re-executes the search.
When viewing results of a search job from the Activity menu, which of the following is displayed?
What are the three main Splunk components?
What can be configured using the Edit Job Settings menu?
Beginning parentheses is automatically highlighted to guide you on the presence of complimenting
parentheses.
Data sources being opened and read applies to:
By default search results are not returned in ________ order.
Which of the following searches will return results where fail, 400, and error exist in every event?
By default, which role contains the minimum permissions required to have write access to Splunk alerts?
When viewing the results of a search, what is an Interesting Field?
Which of the following are not true about lookups? (Select all that apply.)
What are Splunk alerts based on?
Which search would return events from the access_combined sourcetype?
When placed early in a search, which command is most effective at reducing search execution time?
By default, all users have DELETE permission to ALL knowledge objects.
Parsing of data can happen both in HF and UF.
_______________ transforms raw data into events and distributes the results into an index.
Lookups allow you to overwrite your raw event.
How many main user roles do you have in Splunk?