SPLK-1001 Splunk Core Certified User Questions and Answers
Which search will return the 15 least common field values for the dest_ip field?
How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?
You can also specify a time range in the search bar. You can use the following for beginning and ending for a
time range (Choose two.):
In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?
Which of the following searches would return events with failure in index netfw or warn or critical in index netops?
Select the correct option that applies to Index time processing (Choose three.).
In the Splunk interface, the list of alerts can be filtered based on which characteristics?
Which Field/Value pair will return only events found in the index named security?
Keywords are highlighted when you mouse over search results and you can click this search result to (Choose three.):
What result will you get with following search index=test sourcetype= " The_Questionnaire_P* " ?
When placed early in a search, which command is most effective at reducing search execution time?
What is the correct syntax to count the number of events containing a vendor_action field?
Which of the following searches would return only events that match the following criteria?
• Events are inside the main index
• The field status exists in the event
• The value in the status field does not equal 200
Beginning parentheses is automatically highlighted to guide you on the presence of complimenting
parentheses.
When looking at a statistics table, what is one way to drill down to see the underlying events?
By default, which of the following fields would be listed in the fields sidebar under interesting Fields?
A collection of items containing things such as data inputs, UI elements, and knowledge objects is known as what?
What is the correct way to use a time range specifier in the search bar so that the search looks back 2 hours?
Which of the following is a correct way to limit search results to display the 5 most common values of a field?
Which of the following is the recommended way to create multiple dashboards displaying data from the same search?
When sorting on multiple fields with the sort command, what delimiter can be used between the field names in the search?
Put query into separate lines where | (Pipes) are used by selecting following options.
When viewing results of a search job from the Activity menu, which of the following is displayed?
You can use the following options to specify start and end time for the query range:
This function of the stats command allows you to return the middle-most value of field X.
When a Splunk search generates calculated data that appears in the Statistics tab. in what formats can the results be exported?
Which of the following file types is an option for exporting Splunk search results?
