Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Splunk SPLK-1001 Dumps

Page: 1 / 18
Total 244 questions

Splunk Core Certified User Exam Questions and Answers

Question 1

When looking at a statistics table, what is one way to drill down to see the underlying events?

Options:

A.

Creating a pivot table.

B.

Clicking on the visualizations tab.

C.

Viewing your report in a dashboard.

D.

Clicking on any field value in the table.

Question 2

In the Search and Reporting app, which is a default selected field?

Options:

A.

index

B.

action

C.

_time

D.

host

Question 3

Which of the following is the best way to create a report that shows the last 24 hours of events?

Options:

A.

Use earliest=-1d@d latest=@d

B.

Set a real-time search over a 24-hour window

C.

Use the time range picket to select “Yesterday”

D.

Use the time range picker to select “Last 24 hours”

Question 4

Which of the following describes lookup files?

Options:

A.

Lookup fields cannot be used in searches

B.

Lookups contain static data available in the index

C.

Lookups add more fields to results returned by a search

D.

Lookups pull data at index time and add them to search results

Question 5

How to make Interesting field into a selected field?

Options:

A.

Click field in field sidebar -> click YES on the pop-up dialog on upper right side -> check now field should

be visible in the list of selected fields.

B.

Not possible.

C.

Only CLI changes will enable it.

D.

Click Settings -> Find field option -> Drop down select field -> enable selected field -> check now field

should be visible in the list of selected fields.

Question 6

What is the primary use for the rare command1?

Options:

A.

To sort field values in descending order

B.

To return only fields containing five or fewer values

C.

To find the least common values of a field in a dataset

D.

To find the fields with the fewest number of values across a dataset

Question 7

What must be done in order to use a lookup table in Splunk?

Options:

A.

The lookup must be configured to run automatically.

B.

The contents of the lookup file must be copied and pasted into the search bar.

C.

The lookup file must be uploaded to Splunk and a lookup definition must be created.

D.

The lookup file must be uploaded to the etc/apps/lookups folder for automatic ingestion.

Question 8

Splunk automatically determines the source type for major data types.

Options:

A.

False

B.

True

Question 9

It is not possible for a single instance of Splunk to manage the input, parsing and indexing of machine.

Options:

A.

True

B.

False

Question 10

You are able to create new Index in Data Input settings.

Options:

A.

No

B.

Yes

Question 11

It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.

Options:

A.

True

B.

False

Question 12

Splunk apps are used for following (Choose three.):

Options:

A.

Designed to cater numerous use cases and empower Splunk.

B.

We can not install Splunk App.

C.

Allows multiple workspaces for different use cases/user roles.

D.

It is collection of different Splunk config files like data inputs, UI and Knowledge Object.

Question 13

You can use the following options to specify start and end time for the query range:

Options:

A.

earliest=

B.

latest=

C.

beginning=

D.

ending=

E.

All the above

F.

Only 3rd and 4th

Question 14

Which search string returns a filed containing the number of matching events and names that field Event Count?

Options:

A.

index=security failure | stats sum as “Event Count”

B.

index=security failure | stats count as “Event Count”

C.

index=security failure | stats count by “Event Count”

D.

index=security failure | stats dc(count) as “Event Count”

Question 15

You can on-board data to Splunk using following means (Choose four.):

Options:

A.

Props

B.

CLI

C.

Splunk Web

D.

savedsearches.conf

E.

Splunk apps and add-ons

F.

indexes.conf

G.

inputs.conf

Question 16

Log filtering/parsing can be done from _____________.

Options:

A.

Index Forwarders (IF)

B.

Universal Forwarders (UF)

C.

Super Forwarder (SF)

D.

Heavy Forwarders (HF)

Question 17

Assuming a user has the capability to edit reports, which of the following are editable?

Options:

A.

Acceleration, schedule, permissions

B.

The report’s name, schedule, permissions

C.

The report’s name, acceleration, schedule

D.

The report’s name, acceleration, permissions

Question 18

How are events displayed after a search is executed?

Options:

A.

In chronological order.

B.

Randomly by default.

C.

In reverse chronological order.

D.

Alphabetically according to field name.

Question 19

What is the primary use for the rare command?

Options:

A.

To sort field values in descending order.

B.

To return only fields containing five of fewer values.

C.

To find the least common values of a field in a dataset.

D.

To find the fields with the fewest number of values across a dataset.

Question 20

Select the correct option that applies to Index time processing (Choose three.).

Options:

A.

Indexing

B.

Searching

C.

Parsing

D.

Settings

E.

Input

Question 21

Three basic components of Splunk are (Choose three.):

Options:

A.

Forwarders

B.

Deployment Server

C.

Indexer

D.

Knowledge Objects

E.

Index

F.

Search Head

Question 22

Which command automatically returns percent and count columns when executing searches?

Options:

A.

top

B.

stats

C.

table

D.

percent

Question 23

What does the stats command do?

Options:

A.

Automatically correlates related fields

B.

Converts field values into numerical values

C.

Calculates statistics on data that matches the search criteria

D.

Analyzes numerical fields for their ability to predict another discrete field

Question 24

Which of the following statements are correct about Search & Reporting App? (Choose three.)

Options:

A.

Can be accessed by Apps > Search & Reporting.

B.

Provides default interface for searching and analyzing logs.

C.

Enables the user to create knowledge object, reports, alerts and dashboards.

D.

It only gives us search functionality.

Question 25

@ Symbol can be used in advanced time unit option.

Options:

A.

No

B.

Yes

Question 26

Splunk Components:

Which of the following are responsible for reducing search results?

Options:

A.

search heads

B.

indexers

C.

forwarders

Question 27

Splunk shows data in __________________.

Options:

A.

ASCII Character order.

B.

Reverse chronological order.

C.

Alphanumeric order.

D.

Chronological order.

Question 28

What is the result of the following search?

index=myindex source=c: \mydata. txt NOT error=*

Options:

A.

Only data where the error field is present and does not contain a value will be displayed.

B.

Only data with a value in the field error will be displayed.

C.

Only data that does not contain the error field will be displayed.

D.

Only data where the value of the field error does not equal an asterisk (*) will be displayed.

Question 29

When a Splunk search generates calculated data that appears in the Statistics tab. in what formats can the results be exported?

Options:

A.

CSV, JSON, PDF

B.

CSV, XML JSON

C.

Raw Events, XML, JSON

D.

Raw Events, CSV, XML, JSON

Question 30

What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?

Options:

A.

the_questionnaire _pedia

B.

the_questionnaire pedia

C.

the_questionnaire_pedia

D.

the_questionnaire Pedia

Question 31

Which of the following fields is stored with the events in the index?

Options:

A.

user

B.

source

C.

location

D.

sourcelp

Question 32

What can be included in the All Fields option in the sidebar?

Options:

A.

Dashboards

B.

Metadata only

C.

Non-interesting fields

D.

Field descriptions

Question 33

In the fields sidebar, what indicates that a field is numeric?

Options:

A.

A number to the right of the field name.

B.

A # symbol to the left of the field name.

C.

A lowercase n to the left of the field name.

D.

A lowercase n to the right of the field name.

Question 34

Select the best options for "search best practices" in Splunk:

(Choose five.)

Options:

A.

Select the time range always.

B.

Try to specify index values.

C.

Include as many search terms as possible.

D.

Never select time range.

E.

Try to use * with every search term.

F.

Inclusion is generally better than exclusion.

G.

Try to keep specific search terms.

Question 35

What is one benefit of creating dashboard panels from reports?

Options:

A.

Any newly created dashboard will include that report.

B.

There are no benefits to creating dashboard panels from reports.

C.

It makes the dashboard more efficient because it only has to run one search string.

D.

Any change to the underlying report will affect every dashboard that utilizes that report.

Question 36

How can search results be kept longer than 7 days?

Options:

A.

By scheduling a report.

B.

By creating a link to the job.

C.

By changing the job settings.

D.

By changing the time range picker to more than 7 days.

Question 37

Portal for Splunk apps can be accessed through

Options:

A.

False

B.

True

Question 38

Which is the default app for Splunk Enterprise?

Options:

A.

Splunk Enterprise Security Suite

B.

Searching and Reporting

C.

Reporting and Searching

D.

Splunk apps for Security

Question 39

The new data uploaded in Splunk are shown in ________________.

Options:

A.

Real-time

B.

10 Minutes

C.

Overnight Download

D.

30 Minutes

Question 40

This function of the stats command allows you to return the middle-most value of field X.

Options:

A.

Median(X)

B.

Eval by X

C.

Fields(X)

D.

Values(X)

Question 41

Which stats command function provides a count of how many unique values exist for a given field in the result set?

Options:

A.

dc(field)

B.

count(field)

C.

count-by(field)

D.

distinct-count(field)

Question 42

Which search will return the 15 least common field values for the dest_ip field?

Options:

A.

sourcetype=firewall | rare num=15 dest_ip

B.

sourcetype=firewall | rare last=15 dest_ip

C.

sourcetype=firewall | rare count=15 dest_ip

D.

sourcetype=firewall | rare limit=15 dest_ip

Question 43

Which is a primary function of the timeline located under the search bar?

Options:

A.

To differentiate between structured and unstructured events in the data

B.

To sort the events returned by the search command in chronological order

C.

To zoom in and zoom out. although this does not change the scale of the chart

D.

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Question 44

Which search string only returns events from hostWWW3?

Options:

A.

B. host=WWW3

B.

C. host=WWW*

C.

D. Host=WWW3

Question 45

Which search will return only events containing the word “error” and display the results as a table that includes

the fields named action, src, and dest?

Options:

A.

error | table action, src, dest

B.

error | tabular action, src, dest

C.

error | stats table action, src, dest

D.

error | table column=action column=src column=dest

Question 46

Which command is used to validate a lookup file?

Options:

A.

| lookup products.csv

B.

inputlookup products.csv

C.

I inputlookup products.csv

D.

| lookup definition products.csv

Question 47

When displaying results of a search, which of the following is true about line charts?

Options:

A.

Line charts are optimal for single and multiple series.

B.

Line charts are optimal for single series when using Fast mode.

C.

Line charts are optimal for multiple series with 3 or more columns.

D.

Line charts are optimal for multiseries searches with at least 2 or more columns.

Question 48

Which time range picker configuration would return real-time events for the past 30 seconds?

Options:

A.

Preset - Relative: 30-seconds ago

B.

Relative - Earliest: 30-seconds ago, Latest: Now

C.

Real-time - Earliest: 30-seconds ago, Latest: Now

D.

Advanced - Earliest: 30-seconds ago, Latest: Now

Question 49

Which of the following reports is available in the Fields window?

Options:

A.

Top values by time

B.

Rare values by time

C.

Events with top value fields

D.

Events with rare value fields

Question 50

Field values are case sensitive.

Options:

A.

True

B.

False

Question 51

In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?

Options:

A.

No events will be returned.

B.

Splunk will prompt you to specify an index.

C.

All non-indexed events to which the user has access will be returned.

D.

Events from every index searched by default to which the user has access will be returned.

Question 52

When looking at a dashboard panel that is based on a report, which of the following is true?

Options:

A.

You can modify the search string in the panel, and you can change and configure the visualization.

B.

You can modify the search string in the panel, but you cannot change and configure the visualization.

C.

You cannot modify the search string in the panel, but you can change and configure the visualization.

D.

You cannot modify the search string in the panel, and you cannot change and configure the visualization.

Question 53

Which statement describes field discovery at search time?

Options:

A.

Splunk automatically discovers only numeric fields

B.

Splunk automatically discovers only alphanumeric fields

C.

Splunk automatically discovers only manually configured fields

D.

Splunk automatically discovers only fields directly related to the search results

Question 54

Universal forwarder is recommended for forwarding the logs to indexers.

Options:

A.

False

B.

True

Question 55

Zoom Out and Zoom to Selection re-executes the search.

Options:

A.

No

B.

Yes

Question 56

When viewing results of a search job from the Activity menu, which of the following is displayed?

Options:

A.

New events based on the current time range picker

B.

The same events based on the current time range picker

C.

The same events from when the original search was executed

D.

New events in addition to the same events from the original search

Question 57

What are the three main Splunk components?

Options:

A.

Search head, GPU, streamer

B.

Search head, indexer, forwarder

C.

Search head, SQL database, forwarder

D.

Search head, SSD, heavy weight agent

Question 58

What can be configured using the Edit Job Settings menu?

Options:

A.

Export the results to CSV format

B.

Add the Job results to a dashboard

C.

Schedule the Job to re-run in 10 minutes

D.

Change Job Lifetime from 10 minutes to 7 days.

Question 59

Beginning parentheses is automatically highlighted to guide you on the presence of complimenting

parentheses.

Options:

A.

No

B.

Yes

Question 60

Data sources being opened and read applies to:

Options:

A.

None of the above

B.

Indexing Phase

C.

Parsing Phase

D.

Input Phase

E.

License Metering

Question 61

By default search results are not returned in ________ order.

Options:

A.

Chronological

B.

Reverser chronological

C.

ASCIE

D.

Alphabetical

Question 62

Which of the following searches will return results where fail, 400, and error exist in every event?

Options:

A.

error AND (fail AND 400)

B.

error OR (fail and 400)

C.

error AND (fail OR 400)

D.

error OR fail OR 400

Question 63

By default, which role contains the minimum permissions required to have write access to Splunk alerts?

Options:

A.

User

B.

Alerting

C.

Power

D.

Admin

Question 64

When viewing the results of a search, what is an Interesting Field?

Options:

A.

A field that appears in any event

B.

A field that appears in every event

C.

A field that appears in the top 10 events

D.

A field that appears in at least 20% of the events

Question 65

Which of the following are not true about lookups? (Select all that apply.)

Options:

A.

Lookups can be time based

B.

Search results can be used to populate a lookup table

C.

Splunk DB Connect can be used to populate a lookup table from relational databases

D.

Output from a script can be used to populate a lookup table

E.

Lookup have a 10mg maximum size limit

Question 66

What are Splunk alerts based on?

Options:

A.

Dashboards

B.

Searches

C.

Webhooks

D.

Reports

Question 67

Which search would return events from the access_combined sourcetype?

Options:

A.

Sourcetype=access_combined

B.

Sourcetype=Access_Combined

C.

sourcetype=Access_Combined

D.

SOURCETYPE=access_combined

Question 68

When placed early in a search, which command is most effective at reducing search execution time?

Options:

A.

dedup

B.

rename

C.

sort -

D.

fields +

Question 69

By default, all users have DELETE permission to ALL knowledge objects.

Options:

A.

True

B.

False

Question 70

Parsing of data can happen both in HF and UF.

Options:

A.

Yes

B.

No

Question 71

_______________ transforms raw data into events and distributes the results into an index.

Options:

A.

Index

B.

Search Head

C.

Indexer

D.

Forwarder

Question 72

Lookups allow you to overwrite your raw event.

Options:

A.

True

B.

False

Question 73

How many main user roles do you have in Splunk?

Options:

A.

2

B.

4

C.

1

D.

3

Page: 1 / 18
Total 244 questions