Black Friday Special Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Splunk > Splunk Core Certified User > SPLK-1001

SPLK-1001 Splunk Core Certified User Question and Answers

Question # 4

Which Field/Value pair will return only events found in the index named security?

A.

Index=Security

B.

index=Security

C.

Index=security

D.

index!=Security

Full Access
Question # 5

Field names are case sensitive.

A.

True

B.

False

Full Access
Question # 6

Which of the following searches will return results where fail, 400, and error exist in every event?

A.

error AND (fail AND 400)

B.

error OR (fail and 400)

C.

error AND (fail OR 400)

D.

error OR fail OR 400

Full Access
Question # 7

_______________ transforms raw data into events and distributes the results into an index.

A.

Index

B.

Search Head

C.

Indexer

D.

Forwarder

Full Access
Question # 8

In the fields sidebar, what indicates that a field is numeric?

A.

A number to the right of the field name.

B.

A # symbol to the left of the field name.

C.

A lowercase n to the left of the field name.

D.

A lowercase n to the right of the field name.

Full Access
Question # 9

How can another user gain access to a saved report?

A.

The owner of the report can edit permissions from the Edit dropdown

B.

Only users with an Admin or Power User role can access other users' reports

C.

Anyone can access any reports marked as public within a shared Splunk deployment

D.

The owner of the report must clone the original report and save it to their user account

Full Access
Question # 10

This search will return 20 results. SEARCH: error | top host limit = 20

A.

True

B.

False

Full Access
Question # 11

What can be configured using the Edit Job Settings menu?

A.

Export the results to CSV format

B.

Add the Job results to a dashboard

C.

Schedule the Job to re-run in 10 minutes

D.

Change Job Lifetime from 10 minutes to 7 days.

Full Access
Question # 12

What user interface component allows for time selection?

A.

Time summary

B.

Time range picker

C.

Search time picker

D.

Data source time statistics

Full Access
Question # 13

How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?

A.

5 minutes

B.

1 minute

C.

10 minutes

D.

60 minutes

Full Access
Question # 14

Search Assistant is enabled by default in the SPL editor with compact settings.

A.

No

B.

Yes

Full Access
Question # 15

The command shown here does witch of the following: Command: |outputlookup products.csv

A.

Writes search results to a file named products.csv

B.

Returns the contents of a file named products.csv

Full Access
Question # 16

Which of the following is the best description of Splunk Apps?

A.

Built only by Splunk employees.

B.

A collection of files.

C.

Only available for download on Splunkbase.

D.

Available on iOS and Android.

Full Access
Question # 17

______________ is the default web port used by Splunk.

A.

8089

B.

8000

C.

8080

D.

443

Full Access
Question # 18

These users can create global knowledge objects. (Select all that apply.)

A.

users

B.

power users

C.

administrators

Full Access
Question # 19

Forward Option gather and forward data to indexers over a receiving port from remote machines.

A.

False

B.

True

Full Access
Question # 20

When using the top command in the following search, which of the following will be true about the results?

index="main" sourcetype="access_*" action="purchase" | top 3 statusCode by user showperc=f countfield=status_code_count

A.

The search will fail. The proper top command format is top limit=3 instead of top 3.

B.

The top three most common values in statusCode will be displayed for each user.

C.

Only the top three overall most common values in statusCode will be displayed.

D.

The percentage field will be displayed in the results.

Full Access
Question # 21

Which search will return the 15 least common field values for the dest_ip field?

A.

sourcetype=firewall | rare num=15 dest_ip

B.

sourcetype=firewall | rare last=15 dest_ip

C.

sourcetype=firewall | rare count=15 dest_ip

D.

sourcetype=firewall | rare limit=15 dest_ip

Full Access
Question # 22

Splunk apps are used for following (Choose three.):

A.

Designed to cater numerous use cases and empower Splunk.

B.

We can not install Splunk App.

C.

Allows multiple workspaces for different use cases/user roles.

D.

It is collection of different Splunk config files like data inputs, UI and Knowledge Object.

Full Access
Question # 23

Portal for Splunk apps can be accessed through www.splunkbase.com

A.

False

B.

True

Full Access
Question # 24

Use this command to use lookup fields in a search and see the lookup fields in the field sidebar.

A.

inputlookup

B.

lookup

Full Access
Question # 25

What is the primary use for the rare command?

A.

To sort field values in descending order.

B.

To return only fields containing five of fewer values.

C.

To find the least common values of a field in a dataset.

D.

To find the fields with the fewest number of values across a dataset.

Full Access
Question # 26

Which of the following represents the Splunk recommended naming convention for dashboards?

A.

Description_Group_Object

B.

Group_Description_Object

C.

Group_Object_Description

D.

Object_Group_Description

Full Access
Question # 27

You can use the following options to specify start and end time for the query range:

A.

earliest=

B.

latest=

C.

beginning=

D.

ending=

E.

All the above

F.

Only 3rd and 4th

Full Access
Question # 28

How does Splunk determine which fields to extract from data?

A.

Splunk only extracts the most interesting data from the last 24 hours.

B.

Splunk only extracts fields users have manually specified in their data.

C.

Splunk automatically extracts any fields that generate interesting visualizations.

D.

Splunk automatically discovers many fields based on sourcetype and key/value pairs found in the data.

Full Access
Question # 29

Which of the following searches will show the number of categoryld used by each host?

A.

Sourcetype=access_* |sum bytes by host

B.

Sourcetype=access_* |stats sum(categorylD) by host

C.

Sourcetype=access_* |sum(bytes) by host

D.

Sourcetype=access_* |stats sum by host

Full Access
Question # 30

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

A.

host

B.

index

C.

source

D.

sourcetype

Full Access
Question # 31

When a search returns __________, you can view the results as a list.

A.

a list of events

B.

transactions

C.

statistical values

Full Access
Question # 32

When sorting on multiple fields with the sort command, what delimiter can be used between the field names in the search?

A.

|

B.

$

C.

!

D.

,

Full Access
Question # 33

Which of the following are Splunk premium enhanced solutions? (Choose three.)

A.

Splunk User Behavior Analytics (UBA)

B.

Splunk IT Service Intelligence (ITSI)

C.

Splunk Enterprise Security (ES)

D.

Splunk Analytics Security (AS)

Full Access
Question # 34

Which of the following statements describes a search job?

A.

Once a search job begins, it cannot be stopped

B.

A search job can only be paused when less than 50% of events are returned

C.

A search job can only be stopped when less than 50% of events are returned

D.

Once a search job begins, it can be stopped or paused at any point in time

Full Access
Question # 35

What is the proper SPL terminology for specifying a particular index in a search?

A.

indexer—index_name

B.

indexer name—index_name

C.

index=index_name

D.

index name=index_name

Full Access
Question # 36

What options do you get after selecting timeline? (Choose four.)

A.

Zoom to selection

B.

Format Timeline

C.

Deselect

D.

Delete

E.

Zoom Out

Full Access
Question # 37

You can view the search result in following format (Choose three.):

A.

Table

B.

Raw

C.

Pie Chart

D.

List

Full Access
Question # 38

Which of the following fields is stored with the events in the index?

A.

user

B.

source

C.

location

D.

sourcelp

Full Access
Question # 39

When saving a search directly to a dashboard panel instead of saving as a report first, which of the following is

created?

A.

Cloned panel

B.

Inline panel

C.

Report panel

D.

Prebuilt panel

Full Access
Question # 40

Fields are searchable key value pairs in your event data.

A.

True

B.

False

Full Access
Question # 41

Prefix wildcards might cause performance issues.

A.

False

B.

True

Full Access
Question # 42

Which stats command function provides a count of how many unique values exist for a given field in the result set?

A.

dc(field)

B.

count(field)

C.

count-by(field)

D.

distinct-count(field)

Full Access
Question # 43

Which of the following statements about case sensitivity is true?

A.

Both field names and field values ARE case sensitive.

B.

Field names ARE case sensitive; field values are NOT.

C.

Field values ARE case sensitive; field names ARE NOT.

D.

Both field names and field values ARE NOT case sensitive.

Full Access
Question # 44

Which search matches the events containing the terms "error" and "fail"?

A.

index=security Error Fail

B.

index=security error OR fail

C.

index=security “error failure”

D.

index=security NOT error NOT fail

Full Access
Question # 45

Which all time unit abbreviations can you include in Advanced time range picker? (Choose seven.)

A.

h

B.

day

C.

mon

D.

yr

E.

y

F.

w

G.

week

Full Access
Question # 46

Which is the default app for Splunk Enterprise?

A.

Splunk Enterprise Security Suite

B.

Searching and Reporting

C.

Reporting and Searching

D.

Splunk apps for Security

Full Access
Question # 47

In the Search and Reporting app, which is a default selected field?

A.

index

B.

action

C.

_time

D.

host

Full Access
Question # 48

What is the correct syntax to count the number of events containing a vendor_action field?

A.

count stats vendor_action

B.

count stats (vendor_action)

C.

stats count (vendor_action)

D.

stats vendor_action (count)

Full Access
Question # 49

What will always appear in the Selected Fields list?

A.

index

B.

action

C.

clientip

D.

sourcetype

Full Access
Question # 50

When writing searches in Splunk, which of the following is true about Booleans?

A.

They must be lowercase.

B.

They must be uppercase.

C.

They must be in quotations.

D.

They must be in parentheses.

Full Access
Question # 51

What does the following specified time range do?

earliest=-72h@h latest=@d

A.

Look back 3 days ago and prior

B.

Look back 72 hours up to one day ago

C.

Look back 72 hours, up to the end of today

D.

Look back from 3 days ago up to the beginning of today

Full Access
Question # 52

Which component of Splunk let us write SPL query to find the required data?

A.

Forwarders

B.

Indexer

C.

Heavy Forwarders

D.

Search head

Full Access
Question # 53

In automatic lookup definitions, the _____ fields are those that are not in the event data.

A.

input

B.

output

Full Access
Question # 54

The four types of Lookups that Splunk provides out-of-the-box are External, KV Store, Geospatial and which of the following?

A.

Correlated

B.

File-based

C.

Total

D.

Segmented

Full Access
Question # 55

Which of the following is the most efficient filter for running searches in Splunk?

A.

Time

B.

Fast mode

C.

Sourcetype

D.

Selected Fields

Full Access
Question # 56

Put query into separate lines where | (Pipes) are used by selecting following options.

A.

CTRL + Enter

B.

Shift + Enter

C.

Space + Enter

D.

ALT + Enter

Full Access
Question # 57

Parsing of data can happen both in HF and Indexer.

A.

Only HF

B.

No

C.

Yes

Full Access
Question # 58

It is mandatory for the lookup file to have this for an automatic lookup to work.

A.

Source type

B.

At least five columns

C.

Timestamp

D.

Input filed

Full Access
Question # 59

When editing a dashboard, which of the following are possible options? (select all that apply)

A.

Add an output.

B.

Export a dashboard panel.

C.

Modify the chart type displayed in a dashboard panel.

D.

Drag a dashboard panel to a different location on the dashboard.

Full Access
Question # 60

Splunk users are assigned roles. Which of the following do roles determine?

A.

Password

B.

Port number

C.

Username

D.

Data access

Full Access
Question # 61

Field values are case sensitive.

A.

True

B.

False

Full Access
Question # 62

By default, all users have DELETE permission to ALL knowledge objects.

A.

True

B.

False

Full Access
Question # 63

Events in Splunk are automatically segregated using data and time.

A.

Yes

B.

No

Full Access
Question # 64

Which of the following is a metadata field assigned to every event in Splunk?

A.

host

B.

owner

C.

bytes

D.

action

Full Access
Question # 65

What type of search can be saved as a report?

A.

Any search can be saved as a report

B.

Only searches that generate visualizations

C.

Only searches containing a transforming command

D.

Only searches that generate statistics or visualizations

Full Access
Question # 66

Following are the time selection option while making search:

(Choose all that apply.)

A.

Date & Time Range

B.

Advanced

C.

Date Range

D.

Presets

E.

Relative

Full Access
Question # 67

In the Splunk interface, the list of alerts can be filtered based on which characteristics?

A.

App, Owner, Severity, and Type

B.

App, Owner, Priority, and Status

C.

App, Dashboard, Severity, and Type

D.

App, Time Window, Type, and Severity

Full Access
Question # 68

Which is a primary function of the timeline located under the search bar?

A.

To differentiate between structured and unstructured events in the data

B.

To sort the events returned by the search command in chronological order

C.

To zoom in and zoom out. although this does not change the scale of the chart

D.

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Full Access
Question # 69

Which search string returns a filed containing the number of matching events and names that field Event Count?

A.

index=security failure | stats sum as “Event Count”

B.

index=security failure | stats count as “Event Count”

C.

index=security failure | stats count by “Event Count”

D.

index=security failure | stats dc(count) as “Event Count”

Full Access
Question # 70

What is the result of the following search?

index=myindex source=c: \mydata. txt NOT error=*

A.

Only data where the error field is present and does not contain a value will be displayed.

B.

Only data with a value in the field error will be displayed.

C.

Only data that does not contain the error field will be displayed.

D.

Only data where the value of the field error does not equal an asterisk (*) will be displayed.

Full Access
Question # 71

Beginning parentheses is automatically highlighted to guide you on the presence of complimenting

parentheses.

A.

No

B.

Yes

Full Access
Question # 72

Which command automatically returns percent and count columns when executing searches?

A.

top

B.

stats

C.

table

D.

percent

Full Access
Question # 73

Which of the following is the most efficient search?

A.

index=* “failed password”

B.

“failed password” index=*

C.

(index=* OR index=security) “failed password”

D.

index=security “failed password”

Full Access