3 Months Free Update
3 Months Free Update
3 Months Free Update
Splunk Components:
Which of the following are responsible for parsing incoming data and storing data on disc?
Which of the following is a correct way to limit search results to display the 5 most common values of a field?
Following are the time selection option while making search:
(Choose all that apply.)
Creating Data Models:
Fields associated with a data set are known as ______.
The four types of Lookups that Splunk provides out-of-the-box are External, KV Store, Geospatial and which of the following?
Selected fields are a set of configurable fields displayed for each event.
What is the correct order of steps for creating a new lookup?
1. Configure the lookup to run automatically
2. Create the lookup table
3. Define the lookup
When writing searches in Splunk, which of the following is true about Booleans?
Which of the following is a metadata field assigned to every event in Splunk?
In the Search and Reporting app, which tab displays timecharts and bar charts?
What is the proper SPL terminology for specifying a particular index in a search?
It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.
After running a search, what effect does clicking and dragging across the timeline have?
Which Boolean operator is implied between search terms, unless otherwise specified?
Which of the following statements are correct about Search & Reporting App? (Choose three.)
Which of the following searches would return events with failure in index netfw or warn or critical in index netops?
Beginning parentheses is automatically highlighted to guide you on the presence of complimenting
parentheses.
Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip
All components are installed and administered in Splunk Enterprise on-premise.
Which Boolean operator is always implied between two search terms, unless otherwise specified?
Which of the following Splunk components typically resides on the machines where data originates?
Which of the following is the most efficient filter for running searches in Splunk?
Which of the following searches will return results where fail, 400, and error exist in every event?
What is the correct way to use a time range specifier in the search bar so that the search looks back 2 hours?