Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Splunk SPLK-1001 Actual Questions

Page: 13 / 18
Total 244 questions

Splunk Core Certified User Exam Questions and Answers

Question 49

Which of the following reports is available in the Fields window?

Options:

A.

Top values by time

B.

Rare values by time

C.

Events with top value fields

D.

Events with rare value fields

Question 50

Field values are case sensitive.

Options:

A.

True

B.

False

Question 51

In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?

Options:

A.

No events will be returned.

B.

Splunk will prompt you to specify an index.

C.

All non-indexed events to which the user has access will be returned.

D.

Events from every index searched by default to which the user has access will be returned.

Question 52

When looking at a dashboard panel that is based on a report, which of the following is true?

Options:

A.

You can modify the search string in the panel, and you can change and configure the visualization.

B.

You can modify the search string in the panel, but you cannot change and configure the visualization.

C.

You cannot modify the search string in the panel, but you can change and configure the visualization.

D.

You cannot modify the search string in the panel, and you cannot change and configure the visualization.

Page: 13 / 18
Total 244 questions