Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Splunk Core Certified User SPLK-1001 Book

Page: 9 / 18
Total 244 questions

Splunk Core Certified User Exam Questions and Answers

Question 33

In the fields sidebar, what indicates that a field is numeric?

Options:

A.

A number to the right of the field name.

B.

A # symbol to the left of the field name.

C.

A lowercase n to the left of the field name.

D.

A lowercase n to the right of the field name.

Question 34

Select the best options for "search best practices" in Splunk:

(Choose five.)

Options:

A.

Select the time range always.

B.

Try to specify index values.

C.

Include as many search terms as possible.

D.

Never select time range.

E.

Try to use * with every search term.

F.

Inclusion is generally better than exclusion.

G.

Try to keep specific search terms.

Question 35

What is one benefit of creating dashboard panels from reports?

Options:

A.

Any newly created dashboard will include that report.

B.

There are no benefits to creating dashboard panels from reports.

C.

It makes the dashboard more efficient because it only has to run one search string.

D.

Any change to the underlying report will affect every dashboard that utilizes that report.

Question 36

How can search results be kept longer than 7 days?

Options:

A.

By scheduling a report.

B.

By creating a link to the job.

C.

By changing the job settings.

D.

By changing the time range picker to more than 7 days.

Page: 9 / 18
Total 244 questions