Following are the time selection option while making search:
(Choose all that apply.)
Which of the following is the most efficient filter for running searches in Splunk?
Will the queries following below get the same result?
1. index=log sourcetype=error_log status !=100
2. index=log sourcetype=error_log NOT status =100
Which of the following Splunk components typically resides on the machines where data originates?
Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip
Which of the following searches would return events with failure in index netfw or warn or critical in index netops?
Which of the following searches would return only events that match the following criteria?
• Events are inside the main index
• The field status exists in the event
• The value in the status field does not equal 200
Data summary button just below the search bar gives you the following (Choose three.):
This function of the stats command allows you to return the sample standard deviation of a field.
_______________ transforms raw data into events and distributes the results into an index.
Put query into separate lines where | (Pipes) are used by selecting following options.
The four types of Lookups that Splunk provides out-of-the-box are External, KV Store, Geospatial and which of the following?
Keywords are highlighted when you mouse over search results and you can click this search result to (Choose three.):
Fields are searchable name and value pairings that differentiates one event from another.
Which of the following statements are correct about Search & Reporting App? (Choose three.)
What happens when a field is added to the Selected Fields list in the fields sidebar'?
When running searches command modifiers in the search string are displayed in what color?