Filters
Question type

Study Flashcards

@ Symbol can be used in advanced time unit option.


A) No
B) Yes

C) A) and B)
D) undefined

Correct Answer

verifed

verified

The new data uploaded in Splunk are shown in ________________.


A) Real-time
B) 10 Minutes
C) Overnight Download
D) 30 Minutes

E) A) and B)
F) A) and C)

Correct Answer

verifed

verified

Data sources being opened and read applies to:


A) None of the above
B) Indexing Phase
C) Parsing Phase
D) Input Phase
E) License Metering

F) A) and B)
G) A) and C)

Correct Answer

verifed

verified

Which of the statements is correct regarding click and drag option in timeline?


A) The new result after selecting the range by dragging filters the events and displays the most recent first.
B) There is no functionality like click and drag in Splunk's timeline.
C) Using this option executes a new query.
D) This doesn't execute a new query.

E) B) and C)
F) A) and B)

Correct Answer

verifed

verified

When saving a search directly to a dashboard panel instead of saving as a report first, which of the following is created?


A) Cloned panel
B) Inline panel
C) Report panel
D) Prebuilt panel

E) B) and D)
F) B) and C)

Correct Answer

verifed

verified

Which of the following statements are correct about Search & Reporting App? (Choose three.)


A) Can be accessed by Apps > Search & Reporting.
B) Provides default interface for searching and analyzing logs.
C) Enables the user to create knowledge object, reports, alerts and dashboards.
D) It only gives us search functionality.

E) All of the above
F) A) and B)

Correct Answer

verifed

verified

Parsing of data can happen both in HF and Indexer.


A) Only HF
B) No
C) Yes

D) All of the above
E) B) and C)

Correct Answer

verifed

verified

Which is primary function of the timeline located under the search bar?


A) To differentiate between structured and unstructured events in the data.
B) To sort the events returned by the search command in chronological order.
C) To zoom in and zoom out, although this does not change the scale of the chart.
D) To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime.

E) B) and D)
F) B) and C)

Correct Answer

verifed

verified

What options do you get after selecting timeline? (Choose four.)


A) Zoom to selection
B) Format Timeline
C) Deselect
D) Delete
E) Zoom Out

F) B) and D)
G) None of the above

Correct Answer

verifed

verified

NOT status = 100:


A) Will display result depending on the data.
B) Will return event where status field exist but value of that field is not 100.
C) Will return event where status field exist but value of that field is not 100 and all events where status field doesn't exist.

D) All of the above
E) B) and C)

Correct Answer

verifed

verified

Which of the following statements about case sensitivity is true?


A) Both field names and field values ARE case sensitive.
B) Field names ARE case sensitive; field values are NOT.
C) Field values ARE case sensitive; field names ARE NOT.
D) Both field names and field values ARE NOT case sensitive.

E) None of the above
F) A) and C)

Correct Answer

verifed

verified

Which of the following fields is stored with the events in the index?


A) user
B) source
C) location
D) sourceIp

E) A) and B)
F) None of the above

Correct Answer

verifed

verified

Splunk automatically determines the source type for major data types.

A) True
B) False

Correct Answer

verifed

verified

At index time, in which field does Splunk store the timestamp value?


A) time
B) _time
C) EventTime
D) timestamp

E) A) and D)
F) B) and D)

Correct Answer

verifed

verified

What happens when a field is added to the Selected Fields list in the fields sidebar?


A) Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field.
B) Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.
C) Custom selections will replace the Interesting Fields that Splunk populated into the list at search time.
D) The selected field and its corresponding values will appear underneath the events in the search results.

E) A) and C)
F) A) and D)

Correct Answer

verifed

verified

When looking at a dashboard panel that is based on a report, which of the following is true?


A) You can modify the search string in the panel, and you can change and configure the visualization.
B) You can modify the search string in the panel, but you cannot change and configure the visualization.
C) You cannot modify the search string in the panel, but you can change and configure the visualization.
D) You cannot modify the search string in the panel, and you cannot change and configure the visualization.

E) A) and D)
F) None of the above

Correct Answer

verifed

verified

Which of the following searches will return results where fail, 400, and error exist in every event?


A) error AND (fail AND 400)
B) error OR (fail and 400)
C) error AND (fail OR 400)
D) error OR fail OR 400

E) All of the above
F) B) and D)

Correct Answer

verifed

verified

What determines the scope of data that appears in a scheduled report?


A) All data accessible to the User role will appear in the report.
B) All data accessible to the owner of the report will appear in the report.
C) All data accessible to all users will appear in the report until the next time the report is run.
D) The owner of the report can configure permissions so that the report uses either the User role or the owner's profile at run time.

E) B) and C)
F) A) and B)

Correct Answer

verifed

verified

Monitor option in Add Data provides _______________.


A) Only continuous monitoring.
B) Only One-time monitoring.
C) None of the above.
D) Both One-time and continuous monitoring.

E) None of the above
F) B) and D)

Correct Answer

verifed

verified

Which of the following Splunk components typically resides on the machines where data originates?


A) Indexer
B) Forwarder
C) Search head
D) Deployment server

E) None of the above
F) C) and D)

Correct Answer

verifed

verified

Showing 141 - 160 of 187

Related Exams

Show Answer