Certbus > Splunk > Splunk Certifications > SPLK-1001 > SPLK-1001 Online Practice Questions and Answers

SPLK-1001 Online Practice Questions and Answers

Questions 4

What is a suggested Splunk best practice for naming reports?

A. Reports are best named using many numbers so they can be more easily sorted.

B. Use a consistent naming convention so they are easily separated by characteristics such as group and object.

C. Name reports as uniquely as possible with no overlap to differentiate them from one another.

D. Any naming convention is fine as long as you keep an external spreadsheet to keep track.

Browse 226 Q&As
Questions 5

What is the purpose of using a by clause with the stats command?

A. To group the results by one or more fields.

B. To compute numerical statistics on each field.

C. To specify how the values in a list are delimited.

D. To partition the input data based on the split-by fields.

Browse 226 Q&As
Questions 6

What can be configured using the Edit Job Settings menu?

A. Export the results to CSV format

B. Add the Job results to a dashboard

C. Schedule the Job to re-run in 10 minutes

D. Change Job Lifetime from 10 minutes to 7 days.

Browse 226 Q&As
Questions 7

Which of the following describes lookup files?

A. Lookup fields cannot be used in searches

B. Lookups contain static data available in the index

C. Lookups add more fields to results returned by a search

D. Lookups pull data at index time and add them to search results

Browse 226 Q&As
Questions 8

When running searches command modifiers in the search string are displayed in what color?

A. Red

B. Blue

C. Orange

D. Highlighted

Browse 226 Q&As
Questions 9

This search will return 20 results. SEARCH: error | top host limit = 20

A. True

B. False

Browse 226 Q&As
Questions 10

When writing searches in Splunk, which of the following is true about Booleans?

A. They must be lowercase.

B. They must be uppercase.

C. They must be in quotations.

D. They must be in parentheses.

Browse 226 Q&As
Questions 11

Which command is used to review the contents of a specified static lookup file?

A. lookup

B. csvlookup

C. inputlookup

D. outputlookup

Browse 226 Q&As
Questions 12

When looking at a statistics table, what is one way to drill down to see the underlying events?

A. Creating a pivot table.

B. Clicking on the visualizations tab.

C. Viewing your report in a dashboard.

D. Clicking on any field value in the table.

Browse 226 Q&As
Questions 13

Data sources being opened and read applies to:

A. None of the above

B. Indexing Phase

C. Parsing Phase

D. Input Phase

E. License Metering

Browse 226 Q&As
Questions 14

Which symbol is used to snap the time?

A. @

B. and

C. *

D. #

Browse 226 Q&As
Questions 15

The better way of writing search query for index is:

A. index=a index=b

B. (index=a OR index=b)

C. index=(a and b)

D. index = a, b

Browse 226 Q&As
Questions 16

When viewing results of a search job from the Activity menu, which of the following is displayed?

A. New events based on the current time range picker

B. The same events based on the current time range picker

C. The same events from when the original search was executed

D. New events in addition to the same events from the original search

Browse 226 Q&As
Questions 17

What is a quick, comprehensive way to learn what data is present in a Splunk deployment?

A. Review Splunk reports

B. Run ./splunk show

C. Click Data Summary in Splunk Web

D. Search index=* sourcetype=* host=*

Browse 226 Q&As
Questions 18

How can results from a specified static lookup file be displayed?

A. lookup command

B. inputlookup command

C. Settings > Lookups > Input

D. Settings > Lookups > Upload

Browse 226 Q&As
Exam Code: SPLK-1001
Exam Name: Splunk Core Certified User
Last Update: Apr 10, 2024
Questions: 226 Q&As

PDF

$45.99

VCE

$49.99

PDF + VCE

$59.99