Splunk Core Power User Exam

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/89

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

90 Terms

1
New cards

Selected fields are displayed ________ each event in the results.

a. below

b. interesting fields

c. other fields

d. above

a. below

2
New cards

Search terms are not case sensitive. (T/F)

True

3
New cards

These two searches will NOT return the same results.

SEARCH 1:login failure SEARCH 2: "login failure" (T/F)

True

4
New cards

A space is implied ______________ in a search string.

a. OR

b. AND

c. ()

d. NOT

b. AND

5
New cards

You can not specify a relative time range, such as 45 seconds ago, for a search (T/F)

False

6
New cards

To use field value data from an event in a Workflow Action, we need to:

a. Create tags for the fields.

b. Select the GET method.

c. Wrap the field in dollar signs.

c. Wrap the field in dollar signs.

7
New cards

This Workflow Action type sends field values to external resources.

a. POST

b. GET

c. Search

a. POST

8
New cards

Workflow Actions can only be applied to a single field.

FALSE

TRUE

False

9
New cards

Hidden fields in a data model:

a. will not be displayed to a Pivot user, but can be used to define other datasets

b. will not be displayed in the dataset editor

c. will be displayed to a Pivot user that has permissions to the field

a. will not be displayed to a Pivot user, but can be used to define other datasets

10
New cards

_____ datasets can be added to a root dataset to narrow down the search.

a. event

b. child

c. parent

d. extracted

b. child

11
New cards

Which of these are NOT Data Model dataset types:

a. Searches

b. Events

c. Transactions

d. Lookups

d. Lookups

12
New cards

You can normalize data for CIM use:

Select all that apply.

a. Using Knowledge Objects.

b. At index time.

c. Only after adding the CIM Add-on.

a. Using Knowledge Objects.

b. At index time.

13
New cards

By default, data models in the CIM Add-on will search across all indexes.

FALSE

TRUE

True

14
New cards

The CIM Add-on indexes extra data and will affect license usage.

FALSE

TRUE

False

15
New cards

How many results are shown by default when using a Top or Rare Command?

10

16
New cards

Warm buckets in Splunk indexes are named by:

a. the timestamps of first and last event in the bucket

b. a naming convention the administrator determines

c. the server that sent the events

a. the timestamps of first and last event in the bucket

17
New cards

Which of the following search modes automatically returns all extracted fields in the fields sidebar?

a. fast

b. smart

c. verbose

C. Verbose

18
New cards

Which type of visualization allows you to show a third dimension of data?

a. bubble chart

b. scatter chart

c. pie chart

d. area chart

a. bubble chart

19
New cards

Which option is NOT available with the chart and timechart commands?

a. usefill

b. useother

c. limit

a. usefill

20
New cards

The ______ clause allows you to define which field is represented on the X axis of a chart.

a. over

b. by

a. over

21
New cards

Which of the following are valid options with the chart command?

Select all that apply.

a. usenull

b. usefield

c. fillfield

d. useother

a. usenull d. useother

22
New cards

The geom command allows you to create:

a. radial gauges

b. standard maps

c. choropleth maps

c. choropleth maps

23
New cards

If you want to format values without changing their characteristics, which would you use?

a. The fieldformat command

b. The eval tostring function

a. The fieldformat command

24
New cards

You can only use one eval command per search.

FALSE

TRUE

False

25
New cards

The eval command 'if' function requires the following three arguments (in order):

a. result if false, result if true, boolean expression

b. boolean expression, result if false, result if true

c. boolean expression, result if true, result if false

d. result if true, result if false, boolean expression

c. boolean expression, result if true, result if false

26
New cards

Mark the terms that fill in the blanks in the correct order: Use _____ to see results of a calculation, or group events on a field value. Use _____ to see events correlated together, or grouped by start and end values.

a. transaction, stats

b. stats, transaction

b. stats, transaction

27
New cards

You can create a transaction based on multiple fields.

TRUE

FALSE

True

28
New cards

Which function should you use with the transaction command to set the maximum total time between the earliest and latest events returned?

a. maxduration

b. maxspan

c. maxpause

d. endswith

b. maxspan

29
New cards

Users with this role can reassign Knowledge Objects.

a. Admin

b. User

c. Power

a. Admin

30
New cards

Knowledge Objects can be used to normalize data.

FALSE

TRUE

True

31
New cards

What are the predefined ways Knowledge Objects can be shared?

a. Specific App

b. Private

c. All Apps

d. Sourcetype

a. Specific App

b. Private

c. All Apps

32
New cards

When extracting fields, we may choose to use our own regular expressions.

FALSE

TRUE

True

33
New cards

During the validation step of the Field Extractor workflow:

You cannot modify the field extraction

You can validate where the data originated from

You can remove values that aren't a match for the field you want to define

34
New cards

Once a field is created using the regex method, you cannot modify the underlying regular expression.

FALSE

TRUE

False

35
New cards

Calculated fields are based on underlying:

a. eval expressions

b. keyword searches

c. stats commands

a. eval expressions

36
New cards

Field aliases are used to _____ data.

a. transform

b. clean

c. calculate

d. normalize

d. normalize

37
New cards

Field aliases can only be applied to a single source type, source, or host.

FALSE

TRUE

False

38
New cards

Tags can be added to Event Types.

FALSE

TRUE

True

39
New cards

These allow you to categorize events based on search terms.

a. Macros

b. Groups

c. Event Types

d. Tags

c. Event Types

40
New cards

You can only add one tag per field value pair.

FALSE

TRUE

False

41
New cards

You can pipe the results of a macro to other commands

FALSE

TRUE

True

42
New cards

What is the proper syntax for using a macro named "us_sales"

a. "us_sales"

b. (us_sales)

c. us_sales

d. `us_sales`

d. `us_sales`

43
New cards

The search expansion tool:

a. Allows you to see what a macro will expand to before you run a search.

b. Automatically fills in the variables before you run a search.

c. Must be used before running a search with a macro.

a. Allows you to see what a macro will expand to before you run a search.

44
New cards

Using the export function, you can export a maximum of 2000 results

TRUE

FALSE

False

45
New cards

Which of the following search control will not re-run the search? (Select all that apply)

a. zoom out

b. selecting a bar on the timeline

c. deselect

d. selecting a range of bars on the timeline

b. selecting a bar on the timeline

c. deselect

d. selecting a range of bars on the timeline

46
New cards

Highlighted search terms indicate ________ search results in Splunk

a. display as a selected field

b. Sorted

c. Charred based on time

d. Matching

d. Matching

47
New cards

The Splunk search language does not support wildcards.

TRUE

FALSE

False

48
New cards

Historical searches provide a static snapshot of events at a given time.

TRUE

FALSE

True

49
New cards

Which of the following Statements about macros is true? (select all that apply)

A. Arguments are defined at execution time.

B. Arguments are defined when the macro is created.

C. Argument values are used to resolve the search string at execution time.

D. Argument values are used to resolve the search string when the macro is created

A. Arguments are defined at execution time.

C. Argument values are used to resolve the search string at execution time.

50
New cards

What is required for a macro to accept three arguments?

A. The macro's name ends with (3).

B. The macro's name starts with (3).

C. The macro's argument count setting is 3 or more.

D. Nothing, all macros can accept any number of arguments.

A. The macro's name ends with (3).

51
New cards

Which of the following statements describes POST workflow actions? A. POST workflow actions are always encrypted.

B. POST workflow actions cannot use field values in their URI.

C. POST workflow actions cannot be created on custom sourcetypes. D. POST workflow actions can open a web page in either the same window or a new .

D. POST workflow actions can open a web page in either the same window or a new .

52
New cards

Which of the following searches show a valid use of macro? (Select all that apply)'

a. index=main source=mySource oldField=* | 'makeMyField(oldField)' | table _time newField

b. index=main source=mySource oldField=* | state if ('makeMyField(oldField ' ) | table _time

c. index=main source=mySource oldField=* | eval newField= 'makeMyField(oldField) ' | table _time

d. index=main source=mySource oldField=* | "'newField('makeMyField(oldField) " ) ' " | table _time

a. index=main source=mySource oldField=* | 'makeMyField(oldField)' | table _time newField

c. index=main source=mySource oldField=* | eval newField= 'makeMyField(oldField) ' | table _time

53
New cards

Which of the following workflow actions can be executed from search results? (select all that apply)

A. GET

B. POST

C. LOOKUP

D. Search

A. GET

B. POST

D. Search

54
New cards

Which of the following is the correct way to use the data model command to search field in the data model within the web dataset? A. | datamodel web search | filed web *

B. | Search datamodel web web | filed web*

C. | datamodel web web field | search web*

D. Datamodel=web | search web | filed web*

A. | datamodel web search | filed web *

55
New cards

Which of the following searches will return events contains a tag name Privileged?

A. Tag= Priv

B. Tag= Priv*

C. Tag= Priv*

D. Tag= Privileged

D. Tag= Privileged

56
New cards

Which of the following statements describes this search? sourcetype=access_combined I transaction JSESSIONID | timechart avg (duration)

A. This is a valid search and will display a timechart of the average duration, of each transaction event.

B. This is a valid search and will display a stats table showing the maximum pause among transactions.

C. No results will be returned because the transaction command must include the startswith and endswith options.

D. No results will be returned because the transaction command must be the last command used in the search pipeline.

A. This is a valid search and will display a timechart of the average duration, of each transaction event.

57
New cards

Calculated fields can be based on which of the following?

A. Tags

B. Extracted fields

C. Output fields for a lookup

D. Fields generated from a search string

B. Extracted fields

58
New cards

When multiple event types with different color values are assigned to the same event, what determines the color displayed for the events? A. Rank

B. Weight

C. Priority

D. Precedence

C. Priority

59
New cards

Which of the following statements describes the command below (select all that apply) sourcetype-access_combined | transaction JSESSIONID

A. An additional filed named maxspan is created.

B. An additional Held named duration is created.

C. An additional field named eventcount is created.

D. Events with the same JSESSIONID will be grouped together into a single event.

B. An additional Held named duration is created.

C. An additional field named eventcount is created.

60
New cards

Which of the following can be used with the eval command tostring function (select all that apply)

A. ''hex''

B. ''commas''

C. ''Decimal''

D. ''duration''

A. ''hex''

B. ''commas''

D. ''duration''

61
New cards

Historical searches provide a static snapshot of event at a given time (T/F)

True

62
New cards

Using the export function, you can export a maximum of 2000 results. (T/F)

False

63
New cards

Which of the following search control will not re-run the search? (select all the apply)

a. zoom out

b. selecting a bar on the timeline

c. deselect

d. selecting a range of the bars on the timeline

b. selecting a bar on the timeline

c. deselect

d. selecting a range of the bars on the timeline

64
New cards

Highlighted search terms indicate ______ search results in splunk.

a. display as selected field

b. sorted

c. chart based on time

d. matching

d. matching

65
New cards

The Splunk search language does not support wildcards (T/F)

False

66
New cards

The Splunk search language supports the + wildcard (T/F)

False

67
New cards

When you mouse over and click to add a search term this (these) boolean operator(s) is(are) not implied (select all that apply

a. OR

b. ( )

c. AND

d. NOT

b. ( )

68
New cards

Using the export function, you can export search results as _____ (select all the apply)

a. XML

b. JSON

c. HTML

d. a PHP file

a. XML

b. JSON

69
New cards

These kinds of fields are identified in your data at INDEX time

a. data-specific fields

b. default fields

b. default fields

70
New cards

Default fields are not added to every event in Splunk at INDEX time.

(T/F)

False

71
New cards

The fields sidebar does not show ______ (select all that apply)

a. interesting fields

b. selected fields

c. all extracted fields

c. all extracted fields

72
New cards

Only Splunk Admins can assign selected fields (T/F)

False

73
New cards

This search user!=*

a. displays only events that contain a value for the user

b. displays all events

c. displays only events that do not contain a value for the user

c. displays only events that do not contain a value for the user

74
New cards

The interesting fields in the fields sidebar is based on what fields you have requested in the past. (T/F)

False

75
New cards

Which mode automatically decides how to return fields based on your search?

a. Verbose

b. Fast

c. Smart

c. Smart

76
New cards

Which search mode returns all fields?

a. Verbose

b. Fast

c. Smart

a. Verbose

77
New cards

Splunk alerts can be based on a search that run _________ (select all the apply)

a. in real time

b. on a regular schedule

c. and have no matching events

a. in real time

b. on a regular schedule

78
New cards

Alert throtting is used to ________

a. verify each alert

b. stagger search request in a time sequenced order

c. stop spamming yourself with alerts

d. check severity

c. stop spamming yourself with alerts

79
New cards

Scheduled alerts must be scheduled to run with cron job syntax only (T/F)

False

80
New cards

A report scheduled to run every 15 mins, but it takes 17 mins to complete in danger of being

a. skipped or deferred

b. automatically accelerated

c. deleted

d. all the above

a. skipped or deferred

81
New cards

Custom charts can be created in the fields sidebar (T/F)

False

82
New cards

Which of the following are valid options to speed up reports?

(select all the apply)

a. Edit permissions

b. Edit description

c. Edit acceleration

d. Edit schedule

c. Edit acceleration

83
New cards

After you create a pivot, you can save it as a _________ (select all the apply)

a. tag

b. eventtype

c. report

d. dashboard panel

c. report

d. dashboard panel

84
New cards

Pivot editor has a map visualization option (T/F)

False

85
New cards

New pivots automatically populate with ______ (select all that apply)

a. Split rows

b. Split columns

c. Count of hosts

d. Time range filter

d. Time range filter

86
New cards

Internal fields, such as _raw and _time can be explicitly removed from results with fields command (T/F)

False

87
New cards

This function on the stats command allows you to return the sample standard deviation of a field.

a. stdev

b. dev

c. count deviation

d. by standarddev

a. stdev

88
New cards

This clause is used to group the output of a stats command by a specific name

a. Rex

b. As

c. List

d. By

a. Rex

89
New cards

When a search returns _________ you can view it as a list

a. a list of events

b. transactions

c. statistical values

c. statistical values

90
New cards

Clicking on a SEGMENT on a chart __________.

a. drills down for that data

b. highlights the field value across the chart

c. add the highlighed value to the search criteria

c. add the highlighed value to the search criteria

Explore top flashcards