Podcast
Questions and Answers
Which search string would only return events from hostWWW3?
Which search string would only return events from hostWWW3?
- host=*
- Host=WWW3
- host=WWW*
- host=WWW3 (correct)
By default, how long does Splunk retain a search job?
By default, how long does Splunk retain a search job?
- 10 Minutes (correct)
- 15 Minutes
- 1 Day
- 7 Days
What must be done before an automatic lookup can be created? (Choose all that apply.)
What must be done before an automatic lookup can be created? (Choose all that apply.)
- The lookup definition must be created. (correct)
- The lookup file must be verified using the inputlookup command.
- The lookup command must be used.
- The lookup file must be uploaded to Splunk.
Which of the following Splunk components typically resides on the machines where data originates?
Which of the following Splunk components typically resides on the machines where data originates?
How can numerical statistics be computed on each field?
How can numerical statistics be computed on each field?
How do you add or remove fields from search results?
How do you add or remove fields from search results?
What should you do if a field exists in search results but isn't being displayed in the fields sidebar?
What should you do if a field exists in search results but isn't being displayed in the fields sidebar?
Which character denotes alphanumeric field values in the fields sidebar?
Which character denotes alphanumeric field values in the fields sidebar?
When configuring permissions for a report in Splunk, what are the options for the report to use at run time?
When configuring permissions for a report in Splunk, what are the options for the report to use at run time?
When writing searches in Splunk, which of the following is true about Booleans?
When writing searches in Splunk, which of the following is true about Booleans?
Which search string would return events with failure in index netfw or warn or critical in index netops?
Which search string would return events with failure in index netfw or warn or critical in index netops?
Select the answer that displays the accurate placing of the pipe in the following search string: index=security sourcetype=access_* status=200 stats count by price
Select the answer that displays the accurate placing of the pipe in the following search string: index=security sourcetype=access_* status=200 stats count by price
Which constraint can be used with the top command in Splunk?
Which constraint can be used with the top command in Splunk?
When editing a dashboard in Splunk, which of the following are possible options? (Choose all that apply.)
When editing a dashboard in Splunk, which of the following are possible options? (Choose all that apply.)
When running searches in Splunk, command modifiers in the search string are displayed in what color?
When running searches in Splunk, command modifiers in the search string are displayed in what color?
Which represents the Splunk recommended naming convention for dashboards?
Which represents the Splunk recommended naming convention for dashboards?
How can search results be kept longer than 7 days in Splunk?
How can search results be kept longer than 7 days in Splunk?
Which of the following is a Splunk search best practice?
Which of the following is a Splunk search best practice?
What effect does clicking and dragging across the timeline have after running a search in Splunk?
What effect does clicking and dragging across the timeline have after running a search in Splunk?
Which command is used to review the contents of a specified static lookup file in Splunk?
Which command is used to review the contents of a specified static lookup file in Splunk?
What must be done in order to use a lookup table in Splunk?
What must be done in order to use a lookup table in Splunk?
When sorting on multiple fields with the sort command in Splunk, what delimiter can be used between the field names in the search?
When sorting on multiple fields with the sort command in Splunk, what delimiter can be used between the field names in the search?
Which time range picker configuration would return real-time events for the past 30 seconds in Splunk?
Which time range picker configuration would return real-time events for the past 30 seconds in Splunk?
What is the correct syntax to count the number of events containing a vendor_action field in Splunk?
What is the correct syntax to count the number of events containing a vendor_action field in Splunk?
What is one benefit of creating dashboard panels from reports in Splunk?
What is one benefit of creating dashboard panels from reports in Splunk?
By default, which of the following fields would be listed in the fields sidebar under interesting Fields in Splunk?
By default, which of the following fields would be listed in the fields sidebar under interesting Fields in Splunk?
Which of the following statements about case sensitivity is true in Splunk?
Which of the following statements about case sensitivity is true in Splunk?
What does the rare command do in Splunk?
What does the rare command do in Splunk?
Flashcards are hidden until you start studying