Splunk Search Queries and Job Lifetimes Quiz
21 Questions
2 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to Lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

What is the correct search string to only return events from hostWWW3?

  • host=*
  • Host=WWW3
  • host=WWW3 (correct)
  • host=WWW*

How long does Splunk retain a search job by default?

  • 15 Minutes
  • 7 Days
  • 10 Minutes (correct)
  • 1 Day

What must be done before an automatic lookup can be created? (Choose all that apply.)

  • The lookup file must be verified using the inputlookup command.
  • The lookup definition must be created. (correct)
  • The lookup command must be used.
  • The lookup file must be uploaded to Splunk.

Which of the following Splunk components typically resides on the machines where data originates?

<p>Forwarder (A)</p> Signup and view all the answers

What determines the scope of data that appears in a scheduled report?

<p>All data accessible to the owner of the report will appear in the report. (A)</p> Signup and view all the answers

What effect does clicking and dragging across the timeline have after running a search in Splunk?

<p>Moves to past or future events. (D)</p> Signup and view all the answers

Which command is used to review the contents of a specified static lookup file in Splunk?

<p>inputlookup (B)</p> Signup and view all the answers

What must be done in order to use a lookup table in Splunk?

<p>The lookup file must be uploaded to Splunk and a lookup definition must be created. (A)</p> Signup and view all the answers

When sorting on multiple fields with the sort command in Splunk, what delimiter can be used between the field names in the search?

<p>, (B)</p> Signup and view all the answers

Which time range picker configuration would return real-time events for the past 30 seconds in Splunk?

<p>Real-time - Earliest: 30-seconds ago, Latest: Now (D)</p> Signup and view all the answers

Which of the following is true about Booleans when writing searches in Splunk?

<p>They must be uppercase. (B)</p> Signup and view all the answers

In Splunk, which search string would return events with failure in index netfw or warn or critical in index netops?

<p>(index=netfw failure) OR (index=netops (warn OR critical)) (B)</p> Signup and view all the answers

Select the answer that displays the accurate placing of the pipe in the following search string: index=security sourcetype=access_* status=200 stats count by price

<p>index=security sourcetype=access_* status=200 | stats count by price (C)</p> Signup and view all the answers

Which of the following constraints can be used with the top command in Splunk?

<p>limit (B)</p> Signup and view all the answers

When editing a dashboard in Splunk, which of the following are possible options? (Choose all that apply.)

<p>Modify the chart type displayed in a dashboard panel. (D)</p> Signup and view all the answers

When running searches, command modifiers in the search string are displayed in what color?

<p>Orange (D)</p> Signup and view all the answers

How can search results be kept longer than 7 days in Splunk?

<p>By changing the job settings. (B)</p> Signup and view all the answers

Which of the following is a Splunk search best practice?

<p>Filter as early as possible. (A)</p> Signup and view all the answers

'When looking at a dashboard panel that is based on a report, which of the following is true?'

<p>You cannot modify the search string in the panel, but you can change and configure the visualization. (D)</p> Signup and view all the answers

Which of the following represents the Splunk recommended naming convention for dashboards?

<p>Group_Object_Description (B)</p> Signup and view all the answers

What is a primary function of a scheduled report in Splunk?

<p>Auto-generated PDF reports of overall data trends. (D)</p> Signup and view all the answers

More Like This

Splunk Search Effects Quiz
28 questions

Splunk Search Effects Quiz

IrresistibleLitotes avatar
IrresistibleLitotes
Splunk Search and Retention Quiz
19 questions
Splunk
3 questions

Splunk

LuminousSage avatar
LuminousSage
Use Quizgecko on...
Browser
Browser