Winter Special Flat 65% Limited Time Discount offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

Splunk SPLK-1001 Splunk Core Certified User Exam Practice Test

Demo: 73 questions
Total 244 questions

Splunk Core Certified User Questions and Answers

Question 1

All users by default have WRITE permission to ALL knowledge objects.

Options:

A.

True

B.

False

Question 2

Which of the following searches would return only events that match the following criteria?

• Events are inside the main index

• The field status exists in the event

• The value in the status field does not equal 200

Options:

A.

index==main status!==200

B.

index=main NOT status=200

C.

index==main NOT status==200

D.

index-main status!=200

Question 3

Beginning parentheses is automatically highlighted to guide you on the presence of complimenting

parentheses.

Options:

A.

No

B.

Yes

Question 4

Which component of Splunk let us write SPL query to find the required data?

Options:

A.

Forwarders

B.

Indexer

C.

Heavy Forwarders

D.

Search head

Question 5

What are Splunk alerts based on?

Options:

A.

Dashboards

B.

Searches

C.

Webhooks

D.

Reports

Question 6

Which of the following searches would return events with failure in index netfw or warn or critical in index netops?

Options:

A.

(index=netfw failure) AND index=netops warn OR critical

B.

(index=netfw failure) OR (index=netops (warn OR critical))

C.

(index=netfw failure) AND (index=netops (warn OR critical))

D.

(index=netfw failure) OR index=netops OR (warn OR critical)

Question 7

Which of the following is a Splunk search best practice?

Options:

A.

Filter as early as possible.

B.

Never specify more than one index.

C.

Include as few search terms as possible.

D.

Use wildcards to return more search results.

Question 8

How can another user gain access to a saved report?

Options:

A.

The owner of the report can edit permissions from the Edit dropdown

B.

Only users with an Admin or Power User role can access other users' reports

C.

Anyone can access any reports marked as public within a shared Splunk deployment

D.

The owner of the report must clone the original report and save it to their user account

Question 9

Parsing of data can happen both in HF and UF.

Options:

A.

Yes

B.

No

Question 10

Which of the following is a metadata field assigned to every event in Splunk?

Options:

A.

host

B.

owner

C.

bytes

D.

action

Question 11

Creating Data Models:

Object ATTRIBUTES do not define ___________.

Options:

A.

a base search for the object

B.

fields for the object

Question 12

Query - status != 100:

Options:

A.

Will return event where status field exist but value of that field is not 100.

B.

Will return event where status field exist but value of that field is not 100 and all events where status field

doesn't exist.

C.

Will get different results depending on data

Question 13

Which of the following statements are correct about Search & Reporting App? (Choose three.)

Options:

A.

Can be accessed by Apps > Search & Reporting.

B.

Provides default interface for searching and analyzing logs.

C.

Enables the user to create knowledge object, reports, alerts and dashboards.

D.

It only gives us search functionality.

Question 14

Every Search in Splunk is also called _____________.

Options:

A.

None of the above

B.

Job

C.

Search Only

Question 15

According to Splunk best practices, which placement of the wildcard results in the most efficient search?

Options:

A.

f*il

B.

*fail

C.

fail*

D.

*fail*

Question 16

This is what Splunk uses to categorize the data that is being indexed.

Options:

A.

sourcetype

B.

index

C.

source

D.

host

Question 17

Which command is used to validate a lookup file?

Options:

A.

| lookup products.csv

B.

inputlookup products.csv

C.

I inputlookup products.csv

D.

| lookup definition products.csv

Question 18

What is the main requirement for creating visualizations using the Splunk UI?

Options:

A.

Your search must transform event data into Excel file format first.

B.

Your search must transform event data into XML formatted data first.

C.

Your search must transform event data into statistical data tables first.

D.

Your search must transform event data into JSON formatted data first.

Question 19

What syntax is used to link key/value pairs in search strings?

Options:

A.

action+purchase

B.

action=purchase

C.

action | purchase

D.

action equal purchase

Question 20

Which search string returns a filed containing the number of matching events and names that field Event Count?

Options:

A.

index=security failure | stats sum as “Event Count”

B.

index=security failure | stats count as “Event Count”

C.

index=security failure | stats count by “Event Count”

D.

index=security failure | stats dc(count) as “Event Count”

Question 21

What is one benefit of creating dashboard panels from reports?

Options:

A.

Any newly created dashboard will include that report.

B.

There are no benefits to creating dashboard panels from reports.

C.

It makes the dashboard more efficient because it only has to run one search string.

D.

Any change to the underlying report will affect every dashboard that utilizes that report.

Question 22

Splunk index time process can be broken down into __________ phases.

Options:

A.

3

B.

2

C.

4

D.

1

Question 23

Documentations for Splunk can be found at docs.splunk.com

Options:

A.

True

B.

False

Question 24

Which of the following is the most efficient filter for running searches in Splunk?

Options:

A.

Time

B.

Fast mode

C.

Sourcetype

D.

Selected Fields

Question 25

Splunk shows data in __________________.

Options:

A.

ASCII Character order.

B.

Reverse chronological order.

C.

Alphanumeric order.

D.

Chronological order.

Question 26

You can on-board data to Splunk using following means (Choose four.):

Options:

A.

Props

B.

CLI

C.

Splunk Web

D.

savedsearches.conf

E.

Splunk apps and add-ons

F.

indexes.conf

G.

inputs.conf

Question 27

Splunk internal fields contains general information about events and starts from underscore i.e. _ .

Options:

A.

True

B.

False

Question 28

Which statement describes field discovery at search time?

Options:

A.

Splunk automatically discovers only numeric fields

B.

Splunk automatically discovers only alphanumeric fields

C.

Splunk automatically discovers only manually configured fields

D.

Splunk automatically discovers only fields directly related to the search results

Question 29

Which of the following index searches would provide the most efficient search performance?

Options:

A.

index=*

B.

index=web OR index=s*

C.

(index=web OR index=sales)

D.

*index=sales AND index=web*

Question 30

Which is a primary function of the timeline located under the search bar?

Options:

A.

To differentiate between structured and unstructured events in the data

B.

To sort the events returned by the search command in chronological order

C.

To zoom in and zoom out. although this does not change the scale of the chart

D.

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Question 31

This is what Splunk uses to categorize the data that is being indexed.

Options:

A.

Host

B.

Sourcetype

C.

Index

D.

Source

Question 32

In the fields sidebar, which character denotes alphanumeric field values?

Options:

A.

#

B.

%

C.

a

D.

a#

Question 33

When looking at a dashboard panel that is based on a report, which of the following is true?

Options:

A.

You can modify the search string in the panel, and you can change and configure the visualization.

B.

You can modify the search string in the panel, but you cannot change and configure the visualization.

C.

You cannot modify the search string in the panel, but you can change and configure the visualization.

D.

You cannot modify the search string in the panel, and you cannot change and configure the visualization.

Question 34

What is the correct way to use a time range specifier in the search bar so that the search looks back 2 hours?

Options:

A.

latest=-2h

B.

earliest=-2h

C.

latest=-2hour@d

D.

earliest=-2hour@d

Question 35

You are able to create new Index in Data Input settings.

Options:

A.

No

B.

Yes

Question 36

What are the three main Splunk components?

Options:

A.

Search head, GPU, streamer

B.

Search head, indexer, forwarder

C.

Search head, SQL database, forwarder

D.

Search head, SSD, heavy weight agent

Question 37

Splunk Components:

Which of the following are responsible for reducing search results?

Options:

A.

search heads

B.

indexers

C.

forwarders

Question 38

Machine data can be in structured and unstructured format.

Options:

A.

False

B.

True

Question 39

When viewing results of a search job from the Activity menu, which of the following is displayed?

Options:

A.

New events based on the current time range picker

B.

The same events based on the current time range picker

C.

The same events from when the original search was executed

D.

New events in addition to the same events from the original search

Question 40

What is Search Assistant in Splunk?

Options:

A.

It is only available to Admins.

B.

Such feature does not exist in Splunk.

C.

Shows options to complete the search string

Question 41

When an alert action is configured to run a script, Splunk must be able to locate the script. Which is one of the directories Splunk will look in to find the script?

Options:

A.

$SPLUNK_HOME/bin/scripts

B.

$SPLUNK_HOME/etc/scripts

C.

$SPLUNK_HOME/bin/etc/scripts

D.

$SPLUNK_HOME/etc/scripts/bin

Question 42

We should use heavy forwarder for sending event-based data to Indexers.

Options:

A.

False

B.

True

Question 43

When a search returns __________, you can view the results as a list.

Options:

A.

a list of events

B.

transactions

C.

statistical values

Question 44

36. Lookups can be private for a user.

Options:

A.

True

B.

False

Question 45

What determines the scope of data that appears in a scheduled report?

Options:

A.

All data accessible to the User role will appear in the report.

B.

All data accessible to the owner of the report will appear in the report.

C.

All data accessible to all users will appear in the report until the next time the report is run.

D.

The owner of the report can configure permissions so that the report uses either the User role or the owner’s profile at run time.

Question 46

Which Field/Value pair will return only events found in the index named security?

Options:

A.

Index=Security

B.

index=Security

C.

Index=security

D.

index!=Security

Question 47

Which search string only returns events from hostWWW3?

Options:

A.

B. host=WWW3

B.

C. host=WWW*

C.

D. Host=WWW3

Question 48

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

Options:

A.

host

B.

index

C.

source

D.

sourcetype

Question 49

What type of search can be saved as a report?

Options:

A.

Any search can be saved as a report

B.

Only searches that generate visualizations

C.

Only searches containing a transforming command

D.

Only searches that generate statistics or visualizations

Question 50

At the time of searching the start time is 03:35:08.

Will it look back to 03:00:00 if we use -30m@h in searching?

Options:

A.

Yes

B.

No

Question 51

You can view the search result in following format (Choose three.):

Options:

A.

Table

B.

Raw

C.

Pie Chart

D.

List

Question 52

Which of the following is an accurate definition of fields within Splunk?

Options:

A.

Inherent entities that exist in event data.

B.

A searchable key/value pair in event data.

C.

Values pulled exclusively from lookup tables.

D.

A non-searchable name/value pair used while indexing data.

Question 53

What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?

Options:

A.

the_questionnaire _pedia

B.

the_questionnaire pedia

C.

the_questionnaire_pedia

D.

the_questionnaire Pedia

Question 54

Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip

Options:

A.

10

B.

50

C.

100

D.

20

Question 55

Fields are searchable key value pairs in your event data.

Options:

A.

True

B.

False

Question 56

What user interface component allows for time selection?

Options:

A.

Time summary

B.

Time range picker

C.

Search time picker

D.

Data source time statistics

Question 57

At index time, in which field does Splunk store the timestamp value?

Options:

A.

time

B.

_time

C.

EventTime

D.

timestamp

Question 58

Matching of parentheses is a feature of Splunk Assistant.

Options:

A.

No

B.

Yes

Question 59

Field values are case sensitive.

Options:

A.

True

B.

False

Question 60

Select the best options for "search best practices" in Splunk:

(Choose five.)

Options:

A.

Select the time range always.

B.

Try to specify index values.

C.

Include as many search terms as possible.

D.

Never select time range.

E.

Try to use * with every search term.

F.

Inclusion is generally better than exclusion.

G.

Try to keep specific search terms.

Question 61

Which search will return only events containing the word “error” and display the results as a table that includes

the fields named action, src, and dest?

Options:

A.

error | table action, src, dest

B.

error | tabular action, src, dest

C.

error | stats table action, src, dest

D.

error | table column=action column=src column=dest

Question 62

When placed early in a search, which command is most effective at reducing search execution time?

Options:

A.

dedup

B.

rename

C.

sort -

D.

fields +

Question 63

Which component of Splunk is primarily responsible for saving data?

Options:

A.

Search Head

B.

Heavy Forwarder

C.

Indexer

D.

Universal Forwarder

Question 64

Which of the following are not true about lookups? (Select all that apply.)

Options:

A.

Lookups can be time based

B.

Search results can be used to populate a lookup table

C.

Splunk DB Connect can be used to populate a lookup table from relational databases

D.

Output from a script can be used to populate a lookup table

E.

Lookup have a 10mg maximum size limit

Question 65

How does Splunk determine which fields to extract from data?

Options:

A.

Splunk only extracts the most interesting data from the last 24 hours.

B.

Splunk only extracts fields users have manually specified in their data.

C.

Splunk automatically extracts any fields that generate interesting visualizations.

D.

Splunk automatically discovers many fields based on sourcetype and key/value pairs found in the data.

Question 66

@ Symbol can be used in advanced time unit option.

Options:

A.

No

B.

Yes

Question 67

In the Search and Reporting app, which is a default selected field?

Options:

A.

index

B.

action

C.

_time

D.

host

Question 68

Monitor option in Add Data provides _______________.

Options:

A.

Only continuous monitoring.

B.

Only One-time monitoring.

C.

None of the above.

D.

Both One-time and continuous monitoring

Question 69

Which of the following is a correct way to limit search results to display the 5 most common values of a field?

Options:

A.

| rare top=5

B.

| top rare=5

C.

| top limit=5

D.

| rare limit=5

Question 70

What does the following specified time range do?

earliest=-72h@h latest=@d

Options:

A.

Look back 3 days ago and prior

B.

Look back 72 hours up to one day ago

C.

Look back 72 hours, up to the end of today

D.

Look back from 3 days ago up to the beginning of today

Question 71

What does the stats command do?

Options:

A.

Automatically correlates related fields

B.

Converts field values into numerical values

C.

Calculates statistics on data that matches the search criteria

D.

Analyzes numerical fields for their ability to predict another discrete field

Question 72

How can results from a specified static lookup file be displayed?

Options:

A.

lookup command

B.

inputlookup command

C.

Settings > Lookups > Input

D.

Settings > Lookups > Upload

Question 73

The better way of writing search query for index is:

Options:

A.

index=a index=b

B.

(index=a OR index=b)

C.

index=(a & b)

D.

index = a, b

Demo: 73 questions
Total 244 questions