Summer Sale Special Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

SPLK-1001 Splunk Core Certified User Questions and Answers

Questions 4

Following are the time selection option while making search:

(Choose all that apply.)

Options:

A.

Date & Time Range

B.

Advanced

C.

Date Range

D.

Presets

E.

Relative

Buy Now
Questions 5

Splunk extracts fields from event data at index time and at search time.

Options:

A.

True

B.

False

Buy Now
Questions 6

Which component of Splunk let us write SPL query to find the required data?

Options:

A.

Forwarders

B.

Indexer

C.

Heavy Forwarders

D.

Search head

Buy Now
Questions 7

Which of the following is the most efficient filter for running searches in Splunk?

Options:

A.

Time

B.

Fast mode

C.

Sourcetype

D.

Selected Fields

Buy Now
Questions 8

Which is the default app for Splunk Enterprise?

Options:

A.

Splunk Enterprise Security Suite

B.

Searching and Reporting

C.

Reporting and Searching

D.

Splunk apps for Security

Buy Now
Questions 9

Will the queries following below get the same result?

1. index=log sourcetype=error_log status !=100

2. index=log sourcetype=error_log NOT status =100

Options:

A.

Yes

B.

No

Buy Now
Questions 10

In the fields sidebar, which character denotes alphanumeric field values?

Options:

A.

#

B.

%

C.

a

D.

a#

Buy Now
Questions 11

Which search string matches only events with the status_code of 4:4?

Options:

A.

status_code !=404

B.

status_code>=400

C.

status_code<=404

D.

status code>403 status_code<405

Buy Now
Questions 12

Which of the following Splunk components typically resides on the machines where data originates?

Options:

A.

Indexer

B.

Forwarder

C.

Search head

D.

Deployment server

Buy Now
Questions 13

Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip

Options:

A.

10

B.

50

C.

100

D.

20

Buy Now
Questions 14

Which is not a comparison operator in Splunk

Options:

A.

<=

B.

=

C.

!=

D.

>

E.

?=

Buy Now
Questions 15

Which of the following searches would return events with failure in index netfw or warn or critical in index netops?

Options:

A.

(index=netfw failure) AND index=netops warn OR critical

B.

(index=netfw failure) OR (index=netops (warn OR critical))

C.

(index=netfw failure) AND (index=netops (warn OR critical))

D.

(index=netfw failure) OR index=netops OR (warn OR critical)

Buy Now
Questions 16

Which of the following searches would return only events that match the following criteria?

• Events are inside the main index

• The field status exists in the event

• The value in the status field does not equal 200

Options:

A.

index==main status!==200

B.

index=main NOT status=200

C.

index==main NOT status==200

D.

index-main status!=200

Buy Now
Questions 17

What syntax is used to link key/value pairs in search strings?

Options:

A.

Parentheses

B.

@ or # symbols

C.

Quotation marks

D.

Relational operators such as =, <, or >

Buy Now
Questions 18

Data summary button just below the search bar gives you the following (Choose three.):

Options:

A.

Hosts

B.

Sourcetypes

C.

Sources

D.

Indexes

Buy Now
Questions 19

When is the pipe character, I, used in search strings?

Options:

A.

Before clauses. For example: stats sum(bytes) | by host

B.

Before commands. For example: | stats sum(bytes) by host

C.

Before arguments. For example: stats sum| (bytes) by host

D.

Before functions. For example: stats |sum(bytes) by host

Buy Now
Questions 20

This function of the stats command allows you to return the sample standard deviation of a field.

Options:

A.

stdev

B.

dev

C.

count deviation

D.

by standarddev

Buy Now
Questions 21

_______________ transforms raw data into events and distributes the results into an index.

Options:

A.

Index

B.

Search Head

C.

Indexer

D.

Forwarder

Buy Now
Questions 22

How does Splunk determine which fields to extract from data?

Options:

A.

Splunk only extracts the most interesting data from the last 24 hours.

B.

Splunk only extracts fields users have manually specified in their data.

C.

Splunk automatically extracts any fields that generate interesting visualizations.

D.

Splunk automatically discovers many fields based on sourcetype and key/value pairs found in the data.

Buy Now
Questions 23

Put query into separate lines where | (Pipes) are used by selecting following options.

Options:

A.

CTRL + Enter

B.

Shift + Enter

C.

Space + Enter

D.

ALT + Enter

Buy Now
Questions 24

Which of the following is the most efficient search?

Options:

A.

index=* “failed password”

B.

“failed password” index=*

C.

(index=* OR index=security) “failed password”

D.

index=security “failed password”

Buy Now
Questions 25

The four types of Lookups that Splunk provides out-of-the-box are External, KV Store, Geospatial and which of the following?

Options:

A.

Correlated

B.

File-based

C.

Total

D.

Segmented

Buy Now
Questions 26

Keywords are highlighted when you mouse over search results and you can click this search result to (Choose three.):

Options:

A.

Open new search.

B.

Exclude the item from search.

C.

None of the above.

D.

Add the item to search

Buy Now
Questions 27

Which of the following statements about case sensitivity is true?

Options:

A.

Both field names and field values ARE case sensitive.

B.

Field names ARE case sensitive; field values are NOT.

C.

Field values ARE case sensitive; field names ARE NOT.

D.

Both field names and field values ARE NOT case sensitive.

Buy Now
Questions 28

This is what Splunk uses to categorize the data that is being indexed.

Options:

A.

sourcetype

B.

index

C.

source

D.

host

Buy Now
Questions 29

Fields are searchable name and value pairings that differentiates one event from another.

Options:

A.

False

B.

True

Buy Now
Questions 30

Which of the following statements are correct about Search & Reporting App? (Choose three.)

Options:

A.

Can be accessed by Apps > Search & Reporting.

B.

Provides default interface for searching and analyzing logs.

C.

Enables the user to create knowledge object, reports, alerts and dashboards.

D.

It only gives us search functionality.

Buy Now
Questions 31

Which is a primary function of the timeline located under the search bar?

Options:

A.

To differentiate between structured and unstructured events in the data

B.

To sort the events returned by the search command in chronological order

C.

To zoom in and zoom out. although this does not change the scale of the chart

D.

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Buy Now
Questions 32

Which of the following is the best description of Splunk Apps?

Options:

A.

Built only by Splunk employees.

B.

A collection of files.

C.

Only available for download on Splunkbase.

D.

Available on iOS and Android.

Buy Now
Questions 33

What can be configured using the Edit Job Settings menu?

Options:

A.

Export the results to CSV format

B.

Add the Job results to a dashboard

C.

Schedule the Job to re-run in 10 minutes

D.

Change Job Lifetime from 10 minutes to 7 days.

Buy Now
Questions 34

What happens when a field is added to the Selected Fields list in the fields sidebar'?

Options:

A.

Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field

B.

Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.

C.

Custom selections will replace the Interesting Fields that Splunk populated into the list at search time

D.

The selected field and its corresponding values will appear underneath the events in the search results

Buy Now
Questions 35

When running searches command modifiers in the search string are displayed in what color?

Options:

A.

Red

B.

Blue

C.

Orange

D.

Highlighted

Buy Now
Exam Code: SPLK-1001
Exam Name: Splunk Core Certified User
Last Update: May 29, 2023
Questions: 237

PDF + Testing Engine

$70.4  $175.99

Testing Engine

$52.8  $131.99
buy now SPLK-1001 testing engine

PDF (Q&A)

$44  $109.99
buy now SPLK-1001 pdf