Splunk qualification test #2

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/78

flashcard set

Earn XP

Description and Tags

Generated from gdrive quizzes

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

79 Terms

1
New cards

What is the main requirement for creating visualizations using the Splunk UI?

Your search must transform event data into statistical data tables first.

2
New cards

What is an Interesting Field?

A field that appears in at least 20% of the events.

3
New cards

Which of the following is the first step in configuring a scheduled alert?

Create a search.

4
New cards

The stats command will create a _ by default.

Table

5
New cards

What syntax is used to link key/value pairs in search strings?

action=purchase

6
New cards

Which of the following Splunk components typically resides on the machines where data originates?

Forwarder

7
New cards

What will ticking the Throttle checkbox achieve when setting up an alert?

Suppress alert triggering for a specific time period.

8
New cards

How are events displayed after a search is executed?

In reverse chronological order.

9
New cards

Which of the following describes lookup files?

Lookups add more fields to results returned by a search.

10
New cards

Clicking a SEGMENT on a chart .

drills down for that value

11
New cards

What is a suggested Splunk best practice for naming reports?

Use a consistent naming convention so they are easily separated by characteristics such as group and object.

12
New cards

This function of the stats command allows you to return the middle-most value of field X

Median(X)

13
New cards

What does the stats command do?

Calculates statistics on data that matches the search criteria.

14
New cards

What are the steps to schedule a report?

After saving the report, click Schedule.

15
New cards

Is it possible for a single instance of Splunk to manage the input, parsing, and indexing of machine data?

True

16
New cards

Which command is used to validate a lookup file?

inputlookup products.csv

17
New cards

What must be done before an automatic lookup can be created?

The lookup definition must be created. The lookup file must be uploaded to Splunk.

18
New cards

Which search string only returns events from host WWW3?

host=WWW3

19
New cards

What should an admin configure to notify a retailer every day at 23:00 about the sales status?

A scheduled alert

20
New cards

In a deployment with multiple indexes, what happens when a search is run without specifying an index?

Events from every index searched by default to which the user has access will be returned.

21
New cards

Which of the following is an option after clicking an item in search results?

Adding the item to the search.

22
New cards

Which command lets you use lookup fields in a search and see them in the field sidebar?

lookup

23
New cards

What is the result of a webhook alert action?

Displaying a message in a chat room or updating another web resource.

24
New cards

By default, how long does Splunk retain a search job?

7 Days

25
New cards

What determines the scope of data that appears in a scheduled report?

The owner of the report can configure permissions so that the report uses either the User role or the owner's profile at run time.

26
New cards

Fields associated with a data set in Data Models are known as .

Attributes

27
New cards

What effect does clicking and dragging across the timeline have after running a search?

Filters current search results.

28
New cards

What does the time range earliest=-72h@h latest=@d do?

Look back from 3 days ago up to the beginning of today.

29
New cards

In automatic lookup definitions, which fields are those not in the event data?

output

30
New cards

Which stats command function returns the sample standard deviation of a field?

stdev

31
New cards

When is the pipe character used in search strings?

Before commands. For example: | stats sum(bytes) by host.

32
New cards

Does snapping round down to the nearest specified unit?

Yes

33
New cards

Are field values case sensitive?

True

34
New cards

When viewing results of a search job from the Activity menu, what is displayed?

The same events from when the original search was executed.

35
New cards

Data sources being opened and read applies to which phase?

Input Phase

36
New cards

Which is a metadata field assigned to every event in Splunk?

host

37
New cards

Are field names case sensitive?

True

38
New cards

Are field names case sensitive?

False

39
New cards

How many main user roles do you have in Splunk?

3

40
New cards

Can documentation for Splunk be found at docs.splunk.com?

True

41
New cards

Every Search in Splunk is also called _.

Job

42
New cards

What is the better way of writing search query for multiple indexes?

(index=a OR index=b)

43
New cards

What options can you select in GUI for monitor input?

Filed & Directories, HTTP Event Collector (HEC), TCP/UDP and Scripts

44
New cards

Does Splunk automatically determine the source type for major data types?

True

45
New cards

Which time range picker configuration would return real-time events for the past 30 seconds?

Real-time - Earliest: 30-seconds ago, Latest: Now

46
New cards

What is Search Assistant in Splunk?

Shows options to complete the search string.

47
New cards

Should we use heavy forwarder for sending event-based data to Indexers?

False

48
New cards

What does the rare command do?

Returns the least common field values of a given field in the results.

49
New cards

How can you change an Interesting field into a selected field?

Click a field in the field sidebar --> click YES on the pop-up dialog on the upper right side next to the Selected label.

50
New cards

Which of the following is a Splunk internal field?

_raw

51
New cards

Can the @ Symbol be used in advanced time unit option?

Yes

52
New cards

Are matching search terms highlighted?

Yes

53
New cards

What transforms raw data into events and distributes the results into an index?

Indexer

54
New cards

Which statements are correct about Search & Reporting App?

Enables the user to create knowledge object, reports, alerts and dashboards. Provides default interface for searching and analyzing logs. Can be accessed by Apps > Search & Reporting.

55
New cards

Which search would return events from the access_combined sourcetype?

sourcetype=access_combined

56
New cards

When saving a search directly to a dashboard panel instead of a report first, what is created?

Inline panel

57
New cards

Which search will return results where fail, 400, and error exist in every event?

error AND (fail AND 400)

58
New cards

Are fields searchable name and value pairings that differentiate one event from another?

True

59
New cards

Which statement describes a search job?

Once a search job begins, it can be stopped or paused at any point in time.

60
New cards

How do you put query into separate lines where pipes are used?

CTRL + Enter

61
New cards

What does the values function of the stats command do?

Lists unique values of a given field.

62
New cards

Which stats command functions provide a count of how many unique values exist for a field?

dc(field) and distinct-count(field)

63
New cards

What is the purpose of using a by clause with the stats command?

To group the results by one or more fields.

64
New cards

When editing a dashboard, which options are possible?

Add an output. Export a dashboard panel. Modify the chart type displayed in a dashboard panel. Drag a dashboard panel to a different location on the dashboard.

65
New cards

Which of the following are common constraints of the top command?

limit, showpercent

66
New cards

Which command automatically returns percent and count columns when executing searches?

top

67
New cards

Which of the following are functions of the stats command?

sum, avg, values

68
New cards

Which of the following commands will show the maximum bytes?

sourcetype=access_* | stats max(bytes)

69
New cards

What is one benefit of creating dashboard panels from reports?

Any change to the underlying report will affect every dashboard that utilizes that report.

70
New cards

Are != and NOT the same arguments?

False

71
New cards

What is Splunk?

Splunk is a software platform to search, analyze and visualize the machine-generated data.

72
New cards

Which search string is the most efficient?

index=security "failed password"

73
New cards

Which search matches the events containing the terms "error" and "fail"?

index=security error OR fail

74
New cards

When placed early in a search, which command is most effective at reducing search execution time?

fields +

75
New cards

Which component of Splunk is primarily responsible for saving data?

Indexer

76
New cards

According to Splunk best practices, which placement of the wildcard results in the most efficient search?

fail*

77
New cards

Are events in Splunk automatically segregated using data and time?

Yes

78
New cards

Which of the following represents the Splunk recommended naming convention for dashboards?

GroupObjectDescription

79
New cards

Where does Licensing meter happen?

Indexer