Filters
Question type

Study Flashcards

Fields are searchable name and value pairings that differentiates one event from another.

Correct Answer

verifed

verified

Search Language Syntax in Splunk can be broken down into the following components. (Choose all that apply.)


A) Search term
B) Command
C) Pipe
D) Functions
E) Arguments
F) Clause

Correct Answer

verifed

verified

How are events displayed after a search is executed?


A) In chronological order.
B) Randomly by default.
C) In reverse chronological order.
D) Alphabetically according to field name.

Correct Answer

verifed

verified

Which of the following are common constraints of the top command?


A) limit, count
B) limit, showpercent
C) limits, countfield
D) showperc, countfield

Correct Answer

verifed

verified

Every Search in Splunk is also called _____________.


A) None of the above
B) Job
C) Search Only

Correct Answer

verifed

verified

When viewing results of a search job from the Activity menu, which of the following is displayed?


A) New events based on the current time range picker
B) The same events based on the current time range picker
C) The same events from when the original search was executed
D) New events in addition to the same events from the original search

Correct Answer

verifed

verified

Which statement describes field discovery at search time?


A) Splunk automatically discovers only numeric fields
B) Splunk automatically discovers only alphanumeric fields
C) Splunk automatically discovers only manually configured fields
D) Splunk automatically discovers only fields directly related to the search results

Correct Answer

verifed

verified

Interesting fields are the fields that have at least 20% of resulting fields.

Correct Answer

verifed

verified

At the time of searching the start time is 03:35:08. Will it look back to 03:00:00 if we use -30m@h in searching?


A) Yes
B) No

Correct Answer

verifed

verified

Fields are searchable key value pairs in your event data.

Correct Answer

verifed

verified

What is a primary function of a scheduled report?


A) Auto-detect changes in performance.
B) Auto-generated PDF reports of overall data trends.
C) Regularly scheduled archiving to keep disk space use low.
D) Triggering an alert in your Splunk instance when certain conditions are met.

Correct Answer

verifed

verified

Which of the following is the most efficient search?


A) index=* "failed password"
B) "failed password" index=*
C) (index=* OR index=security) "failed password"
D) index=security "failed password"

Correct Answer

verifed

verified

When placed early in a search, which command is most effective at reducing search execution time?


A) dedup
B) rename
C) sort -
D) fields +

Correct Answer

verifed

verified

!= and NOT are same arguments.

Correct Answer

verifed

verified

What is the purpose of using a by clause with the stats command?


A) To group the results by one or more fields.
B) To compute numerical statistics on each field.
C) To specify how the values in a list are delimited.
D) To partition the input data based on the split-by fields.

Correct Answer

verifed

verified

Which of the following is the recommended way to create multiple dashboards displaying data from the same search?


A) Save the search as a report and use it in multiple dashboards as needed.
B) Save the search as a dashboard panel for each dashboard that needs the data.
C) Save the search as a scheduled alert and use it in multiple dashboards as needed.
D) Export the results of the search to an XML file and use the file as the basis of the dashboards.

Correct Answer

verifed

verified

You can change the App context in Input setting.


A) No
B) Yes

Correct Answer

verifed

verified

Field names are case sensitive and field value are not.

Correct Answer

verifed

verified

Which of the following are functions of the stats command?


A) count, sum, add
B) count, sum, less
C) sum, avg, values
D) sum, values, table

Correct Answer

verifed

verified

What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?


A) the_questionnaire _pedia
B) the_questionnaire pedia
C) the_questionnaire_pedia
D) the_questionnaire Pedia

Correct Answer

verifed

verified

Showing 61 - 80 of 187

Related Exams

Show Answer