Intro to Splunk

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/11

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

12 Terms

1
New cards

Which of the following booleans can be used in a search?

ALSO

OR

NOT

AND

OR

NOT

AND

2
New cards

Which search mode behaves differently depending on the type of search being run?

Variable

Fast

Smart

Verbose

Smart

3
New cards

When a search is run, in what order are events returned?

Alphanumeric order

Reverse chronological order

Chronological order

Reverse alphanumeric order

Reverse chronological order

4
New cards

Which Splunk infrastructure component stores ingested data?

Index

Datasets

Dashboards

Data models

Index maybe dashboards?

5
New cards

What is the most efficient way to limit search results returned?

host

source

time

index

time

6
New cards

Which of the following searches will return results containing the words fail, failure, or failed?

fail

*fail

fail+

fail*

fail*

7
New cards

Which of the following searches will return results containing the phrase "failed password"?

"failed password"

failed password

`failed password`

(failed password)

"failed password"

failed password

8
New cards

By default, how long does a search job remain active?

30 minutes

7 days

10 minutes

10 minutes

9
New cards

Which command can be used to further filter results in a search?

filter

subset

subsearch

search

filter

10
New cards

What determines the timestamp shown on returned events in a search?

Timestamps are displayed in Greenwich Mean Time

Timestamps are displayed in epoch time

The time zone defined in user settings

The time zone where the event originated

The time zone defined in user settings

11
New cards

What are the default roles in Splunk Enterprise?

Admin

User

Manager

Power

Admin, User, Power

12
New cards

Which character is used in a search before a command?

A pipe (|)

A backtick (`)

A quotation mark (")

A tilde (~)

A pipe (|)