Easter Special Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

SPLK-1001 Sample Questions Answers

Questions 4

Every Search in Splunk is also called _____________.

Options:

A.

None of the above

B.

Job

C.

Search Only

Buy Now
Questions 5

Which search string only returns events from hostWWW3?

Options:

A.

B. host=WWW3

B.

C. host=WWW*

C.

D. Host=WWW3

Buy Now
Questions 6

A field exists in search results, but isn’t being displayed in the fields sidebar. How can it be added to the fields sidebar?

Options:

A.

Click All Fields and select the field to add it to Selected Fields.

B.

Click Interesting Fields and select the field to add it to Selected Fields.

C.

Click Selected Fields and select the field to add it to Interesting Fields.

D.

This scenario isn’t possible because all fields returned from a search always appear in the fields sidebar.

Buy Now
Questions 7

Portal for Splunk apps can be accessed through www.splunkbase.com

Options:

A.

False

B.

True

Buy Now
Questions 8

Splunk automatically determines the source type for major data types.

Options:

A.

False

B.

True

Buy Now
Questions 9

What is the result of the following search?

index=myindex source=c: \mydata. txt NOT error=*

Options:

A.

Only data where the error field is present and does not contain a value will be displayed.

B.

Only data with a value in the field error will be displayed.

C.

Only data that does not contain the error field will be displayed.

D.

Only data where the value of the field error does not equal an asterisk (*) will be displayed.

Buy Now
Questions 10

Which of the following statements describes a search job?

Options:

A.

Once a search job begins, it cannot be stopped

B.

A search job can only be paused when less than 50% of events are returned

C.

A search job can only be stopped when less than 50% of events are returned

D.

Once a search job begins, it can be stopped or paused at any point in time

Buy Now
Questions 11

Field values are case sensitive.

Options:

A.

True

B.

False

Buy Now
Questions 12

Which of the following is true about user account settings and preferences?

Options:

A.

Search & Reporting is the only app that can be set as the default application.

B.

Full names can only be changed by accounts with a Power User or Admin role.

C.

Time zones are automatically updated based on the setting of the computer accessing Splunk.

D.

Full name, time zone, and default app can be defined by clicking the login name in the Splunk bar.

Buy Now
Questions 13

Which Boolean operator is implied between search terms, unless otherwise specified?

Options:

A.

OR

B.

AND

C.

NOT

D.

NAND

Buy Now
Questions 14

Search Assistant is enabled by default in the SPL editor with compact settings.

Options:

A.

No

B.

Yes

Buy Now
Questions 15

Which command is used to validate a lookup file?

Options:

A.

| lookup products.csv

B.

inputlookup products.csv

C.

I inputlookup products.csv

D.

| lookup definition products.csv

Buy Now
Questions 16

Lookups allow you to overwrite your raw event.

Options:

A.

True

B.

False

Buy Now
Questions 17

It is mandatory for the lookup file to have this for an automatic lookup to work.

Options:

A.

Source type

B.

At least five columns

C.

Timestamp

D.

Input filed

Buy Now
Questions 18

Which Boolean operator is always implied between two search terms, unless otherwise specified?

Options:

A.

OR

B.

NOT

C.

AND

D.

XOR

Buy Now
Questions 19

What must be done in order to use a lookup table in Splunk?

Options:

A.

The lookup must be configured to run automatically.

B.

The contents of the lookup file must be copied and pasted into the search bar.

C.

The lookup file must be uploaded to Splunk and a lookup definition must be created.

D.

The lookup file must be uploaded to the etc/apps/lookups folder for automatic ingestion.

Buy Now
Questions 20

What does the values function of the stats command do?

Options:

A.

Lists all values of a given field.

B.

Lists unique values of a given field.

C.

Returns a count of unique values for a given field.

D.

Returns the number of events that match the search.

Buy Now
Questions 21

When displaying results of a search, which of the following is true about line charts?

Options:

A.

Line charts are optimal for single and multiple series.

B.

Line charts are optimal for single series when using Fast mode.

C.

Line charts are optimal for multiple series with 3 or more columns.

D.

Line charts are optimal for multiseries searches with at least 2 or more columns.

Buy Now
Questions 22

Selected fields are a set of configurable fields displayed for each event.

Options:

A.

True

B.

False

Buy Now
Questions 23

What are Splunk alerts based on?

Options:

A.

Dashboards

B.

Searches

C.

Webhooks

D.

Reports

Buy Now
Questions 24

Which of the following is a Splunk internal field?

Options:

A.

_raw

B.

host

C.

_host

D.

index

Buy Now
Questions 25

Which command will rename action to Customer Action?

Options:

A.

| rename action = CustomerAction

B.

| rename Action as “Customer Action”

C.

| rename Action to “Customer Action”

D.

| rename action as “Customer Action”

Buy Now
Questions 26

Splunk Components:

Which of the following are responsible for reducing search results?

Options:

A.

search heads

B.

indexers

C.

forwarders

Buy Now
Questions 27

What are the two most efficient search filters?

Options:

A.

_time and host

B.

_time and index

C.

host and sourcetype

D.

index and sourcetype

Buy Now
Questions 28

What is Search Assistant in Splunk?

Options:

A.

It is only available to Admins.

B.

Such feature does not exist in Splunk.

C.

Shows options to complete the search string

Buy Now
Questions 29

How are events displayed after a search is executed?

Options:

A.

In chronological order.

B.

Randomly by default.

C.

In reverse chronological order.

D.

Alphabetically according to field name.

Buy Now
Questions 30

What syntax is used to link key/value pairs in search strings?

Options:

A.

action+purchase

B.

action=purchase

C.

action | purchase

D.

action equal purchase

Buy Now
Questions 31

When viewing results of a search job from the Activity menu, which of the following is displayed?

Options:

A.

New events based on the current time range picker

B.

The same events based on the current time range picker

C.

The same events from when the original search was executed

D.

New events in addition to the same events from the original search

Buy Now
Questions 32

What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?

Options:

A.

the_questionnaire _pedia

B.

the_questionnaire pedia

C.

the_questionnaire_pedia

D.

the_questionnaire Pedia

Buy Now
Questions 33

When using the top command in the following search, which of the following will be true about the results?

index="main" sourcetype="access_*" action="purchase" | top 3 statusCode by user showperc=f countfield=status_code_count

Options:

A.

The search will fail. The proper top command format is top limit=3 instead of top 3.

B.

The top three most common values in statusCode will be displayed for each user.

C.

Only the top three overall most common values in statusCode will be displayed.

D.

The percentage field will be displayed in the results.

Buy Now
Questions 34

What is the proper SPL terminology for specifying a particular index in a search?

Options:

A.

indexer—index_name

B.

indexer name—index_name

C.

index=index_name

D.

index name=index_name

Buy Now
Questions 35

Parsing of data can happen both in HF and Indexer.

Options:

A.

Only HF

B.

No

C.

Yes

Buy Now
Questions 36

How can search results be kept longer than 7 days?

Options:

A.

By scheduling a report.

B.

By creating a link to the job.

C.

By changing the job settings.

D.

By changing the time range picker to more than 7 days.

Buy Now
Questions 37

Assuming a user has the capability to edit reports, which of the following are editable?

Options:

A.

Acceleration, schedule, permissions

B.

The report’s name, schedule, permissions

C.

The report’s name, acceleration, schedule

D.

The report’s name, acceleration, permissions

Buy Now
Questions 38

Splunk internal fields contains general information about events and starts from underscore i.e. _ .

Options:

A.

True

B.

False

Buy Now
Questions 39

You can view the search result in following format (Choose three.):

Options:

A.

Table

B.

Raw

C.

Pie Chart

D.

List

Buy Now
Questions 40

Fields are searchable name and value pairings that differentiates one event from another.

Options:

A.

False

B.

True

Buy Now
Questions 41

These users can create global knowledge objects. (Select all that apply.)

Options:

A.

users

B.

power users

C.

administrators

Buy Now
Questions 42

What is the purpose of using a by clause with the stats command?

Options:

A.

To group the results by one or more fields.

B.

To compute numerical statistics on each field.

C.

To specify how the values in a list are delimited.

D.

To partition the input data based on the split-by fields.

Buy Now
Questions 43

Prefix wildcards might cause performance issues.

Options:

A.

False

B.

True

Buy Now
Questions 44

What is the correct order of steps for creating a new lookup?

1. Configure the lookup to run automatically

2. Create the lookup table

3. Define the lookup

Options:

A.

2, 1, 3

B.

1, 2, 3

C.

2, 3, 1

D.

3, 2, 1

Buy Now
Questions 45

What is the main requirement for creating visualizations using the Splunk UI?

Options:

A.

Your search must transform event data into Excel file format first.

B.

Your search must transform event data into XML formatted data first.

C.

Your search must transform event data into statistical data tables first.

D.

Your search must transform event data into JSON formatted data first.

Buy Now
Questions 46

What is a quick, comprehensive way to learn what data is present in a Splunk deployment?

Options:

A.

Review Splunk reports

B.

Run ./splunk show

C.

Click Data Summary in Splunk Web

D.

Search index=* sourcetype=* host=*

Buy Now
Questions 47

Splunk Enterprise is used as a Scalable service in Splunk Cloud.

Options:

A.

True

B.

False

Buy Now
Questions 48

Forward Option gather and forward data to indexers over a receiving port from remote machines.

Options:

A.

False

B.

True

Buy Now
Questions 49

Which of the following fields is stored with the events in the index?

Options:

A.

user

B.

source

C.

location

D.

sourcelp

Buy Now
Questions 50

What is the primary use for the rare command?

Options:

A.

To sort field values in descending order.

B.

To return only fields containing five of fewer values.

C.

To find the least common values of a field in a dataset.

D.

To find the fields with the fewest number of values across a dataset.

Buy Now
Questions 51

Which of the following are functions of the stats command?

Options:

A.

count, sum, add

B.

count, sum, less

C.

sum, avg, values

D.

sum, values, table

Buy Now
Questions 52

By default, which of the following is a Selected Field?

Options:

A.

action

B.

clientip

C.

categoryld

D.

sourcetype

Buy Now
Questions 53

What happens when a field is added to the Selected Fields list in the fields sidebar'?

Options:

A.

Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field

B.

Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.

C.

Custom selections will replace the Interesting Fields that Splunk populated into the list at search time

D.

The selected field and its corresponding values will appear underneath the events in the search results

Buy Now
Questions 54

Data sources being opened and read applies to:

Options:

A.

None of the above

B.

Indexing Phase

C.

Parsing Phase

D.

Input Phase

E.

License Metering

Buy Now
Questions 55

When looking at a dashboard panel that is based on a report, which of the following is true?

Options:

A.

You can modify the search string in the panel, and you can change and configure the visualization.

B.

You can modify the search string in the panel, but you cannot change and configure the visualization.

C.

You cannot modify the search string in the panel, but you can change and configure the visualization.

D.

You cannot modify the search string in the panel, and you cannot change and configure the visualization.

Buy Now
Questions 56

Which of the following is the most efficient search?

Options:

A.

index=* “failed password”

B.

“failed password” index=*

C.

(index=* OR index=security) “failed password”

D.

index=security “failed password”

Buy Now
Questions 57

Three basic components of Splunk are (Choose three.):

Options:

A.

Forwarders

B.

Deployment Server

C.

Indexer

D.

Knowledge Objects

E.

Index

F.

Search Head

Buy Now
Questions 58

How are the results of the following search sorted?

… | sort action, —file, +bytes

Options:

A.

In descending order by action, then descending order by file, and lastly by ascending order of bytes.

B.

In ascending order by action, then descending order by file, and lastly by ascending order of bytes.

C.

In descending order by action if it exists. If not, then in descending order by file, and if both action and file do not exist, by ascending order of bytes.

D.

In ascending order by action if it exists. If not, then in descending order by file, and if both action and file do not exist, by ascending order of bytes.

Buy Now
Questions 59

Which of the following file types is an option for exporting Splunk search results?

Options:

A.

PDF

B.

JSON

C.

XLS

D.

RTF

Buy Now
Questions 60

All users by default have WRITE permission to ALL knowledge objects.

Options:

A.

True

B.

False

Buy Now
Questions 61

What syntax is used to link key/value pairs in search strings?

Options:

A.

Parentheses

B.

@ or # symbols

C.

Quotation marks

D.

Relational operators such as =, <, or >

Buy Now
Questions 62

What user interface component allows for time selection?

Options:

A.

Time summary

B.

Time range picker

C.

Search time picker

D.

Data source time statistics

Buy Now
Questions 63

The four types of Lookups that Splunk provides out-of-the-box are External, KV Store, Geospatial and which of the following?

Options:

A.

Correlated

B.

File-based

C.

Total

D.

Segmented

Buy Now
Questions 64

!= and NOT are same arguments.

Options:

A.

True

B.

False

Buy Now
Questions 65

This is what Splunk uses to categorize the data that is being indexed.

Options:

A.

sourcetype

B.

index

C.

source

D.

host

Buy Now
Questions 66

36. Lookups can be private for a user.

Options:

A.

True

B.

False

Buy Now
Questions 67

Splunk shows data in __________________.

Options:

A.

ASCII Character order.

B.

Reverse chronological order.

C.

Alphanumeric order.

D.

Chronological order.

Buy Now
Questions 68

Creating Data Models:

Object ATTRIBUTES do not define ___________.

Options:

A.

a base search for the object

B.

fields for the object

Buy Now
Questions 69

Which of the following searches will show the number of categoryld used by each host?

Options:

A.

Sourcetype=access_* |sum bytes by host

B.

Sourcetype=access_* |stats sum(categorylD) by host

C.

Sourcetype=access_* |sum(bytes) by host

D.

Sourcetype=access_* |stats sum by host

Buy Now
Questions 70

What is the default lifetime of every Splunk search job?

Options:

A.

All search jobs are saved for 10 days

B.

All search jobs are saved for 10 hours

C.

All search jobs are saved for 10 weeks

D.

All search jobs are saved for 10 minutes

Buy Now
Questions 71

Query - status != 100:

Options:

A.

Will return event where status field exist but value of that field is not 100.

B.

Will return event where status field exist but value of that field is not 100 and all events where status field

doesn't exist.

C.

Will get different results depending on data

Buy Now
Questions 72

Which of the following describes lookup files?

Options:

A.

Lookup fields cannot be used in searches

B.

Lookups contain static data available in the index

C.

Lookups add more fields to results returned by a search

D.

Lookups pull data at index time and add them to search results

Buy Now
Questions 73

The new data uploaded in Splunk are shown in ________________.

Options:

A.

Real-time

B.

10 Minutes

C.

Overnight Download

D.

30 Minutes

Buy Now
Exam Code: SPLK-1001
Exam Name: Splunk Core Certified User
Last Update: May 16, 2024
Questions: 244
$64  $159.99
$48  $119.99
$40  $99.99
buy now SPLK-1001