Splunk Core Certified User Questions and Answers
Which all time unit abbreviations can you include in Advanced time range picker? (Choose seven.)
By default, which role contains the minimum permissions required to have write access to Splunk alerts?
Documentations for Splunk can be found at docs.splunk.com
Which of the following is a correct way to limit search results to display the 5 most common values of a field?
You can view the search result in following format (Choose three.):
Parsing of data can happen both in HF and UF.
Which search would return events from the access_combined sourcetype?
Which of the following is the best description of Splunk Apps?
Which stats command function provides a count of how many unique values exist for a given field in the result set?
We should use heavy forwarder for sending event-based data to Indexers.
Which statement is true about Splunk alerts?
What is a suggested Splunk best practice for naming reports?
Use this command to use lookup fields in a search and see the lookup fields in the field sidebar.
How are events displayed after a search is executed?
What kind of logs can Splunk Index?
After running a search, what effect does clicking and dragging across the timeline have?
How can search results be kept longer than 7 days?
What syntax is used to link key/value pairs in search strings?
Lookups allow you to overwrite your raw event.
A collection of items containing things such as data inputs, UI elements, and knowledge objects is known as what?
Which time range picker configuration would return real-time events for the past 30 seconds?
Which Boolean operator is always implied between two search terms, unless otherwise specified?
Which statement describes field discovery at search time?
How can another user gain access to a saved report?
Prefix wildcards might cause performance issues.
There are three different search modes in Splunk (Choose three.):
Which of the following is true about user account settings and preferences?
Which events will be returned by the following search string?
host=www3 status=503
Every Search in Splunk is also called _____________.
By default search results are not returned in ________ order.
Can you stop or pause the searching?
Which command is used to review the contents of a specified static lookup file?
Which component of Splunk is primarily responsible for saving data?
Which of the following fields is stored with the events in the index?
Which of the following describes lookup files?
Which of the following is the most efficient search?
Monitor option in Add Data provides _______________.
What determines the scope of data that appears in a scheduled report?
You can on-board data to Splunk using following means (Choose four.):
Which search will return only events containing the word “error” and display the results as a table that includes
the fields named action, src, and dest?
What is the correct syntax to count the number of events containing a vendor_action field?
How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?
What can be configured using the Edit Job Settings menu?
What must be done in order to use a lookup table in Splunk?
How do you add or remove fields from search results?
Which of the following file types is an option for exporting Splunk search results?
What is a primary function of a scheduled report?
Which of the following is a Splunk internal field?
Which command automatically returns percent and count columns when executing searches?
What is the primary use for the rare command1?
Field names are case sensitive and field value are not.
The default host name used in Inputs general settings can not be changed.
Which statement is true about the top command?
Which of the following reports is available in the Fields window?
What is the correct order of steps for creating a new lookup?
1. Configure the lookup to run automatically
2. Create the lookup table
3. Define the lookup
It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.
This search will return 20 results. SEARCH: error | top host limit = 20
!= and NOT are same arguments.
Keywords are highlighted when you mouse over search results and you can click this search result to (Choose three.):
Splunk Components:
Which of the following are responsible for parsing incoming data and storing data on disc?
Data sources being opened and read applies to:
Field names are case sensitive.
When writing searches in Splunk, which of the following is true about Booleans?
Which is a primary function of the timeline located under the search bar?
Which search will return the 15 least common field values for the dest_ip field?
______________ is the default web port used by Splunk.
Which is the default app for Splunk Enterprise?
Which of the following statements describes a search job?
Which of the following are Splunk premium enhanced solutions? (Choose three.)
What are Splunk alerts based on?
What is the primary use for the rare command?
Select the answer that displays the accurate placing of the pipe in the following search string:
index=security sourcetype=access_* status=200 stats count by price
When using the top command in the following search, which of the following will be true about the results?
index="main" sourcetype="access_*" action="purchase" | top 3 statusCode by user showperc=f countfield=status_code_count