Exit demo SPLK-1001 Splunk Core Certified User PDF format · free preview

Splunk SPLK-1001 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/splk-1001.html

Question 1
Single choice

Which search will return only events containing the word "error" and display the results as a table that includes the fields named action, src, and dest?

A.

error | table action, src, dest

B.

error | tabular action, src, dest

C.

error | stats table action, src, dest

D.

error | table column=action column=src column=dest

Question 2
Single choice

Select the answer that displays the accurate placing of the pipe in the following search string:

index=security sourcetype=access_* status=200 stats count by price

A.

index=security sourcetype=access_* status=200 stats | count by price

B.

index=security sourcetype=access_* status=200 | stats count by price

C.

index=security sourcetype=access_* status=200 | stats count | by price

D.

index=security sourcetype=access_* | status=200 | stats count by price

Question 3
Single choice

What can be configured using the Edit Job Settings menu?

A.

Export the results to CSV format

B.

Add the Job results to a dashboard

C.

Schedule the Job to re-run in 10 minutes

D.

Change Job Lifetime from 10 minutes to 7 days.

Question 4
Multiple choice

You can view the search result in following format (Choose three.):

A.

Table

B.

Raw

C.

Pie Chart

D.

List

Question 5
Single choice

What is the correct way to use a time range specifier in the search bar so that the search looks back 2 hours?

A.

latest=-2h

B.

earliest=-2h

C.

latest=-2hour@d

D.

earliest=-2hour@d

Question 6
Single choice

What is the correct syntax to count the number of events containing a vendor_action field?

A.

count stats vendor_action

B.

count stats (vendor_action)

C.

stats count (vendor_action)

D.

stats vendor_action (count)

Question 7
Multiple choice

These users can create global knowledge objects. (Select all that apply.)

A.

users

B.

power users

C.

administrators

Question 8
Single choice

NOT status = 100:

A.

Will display result depending on the data.

B.

Will return event where status field exist but value of that field is not 100.

C.

Will return event where status field exist but value of that field is not 100 and all events where status
field doesn't exist.

Question 9
Single choice

Fields are searchable key value pairs in your event data.

A.

True

B.

False

Question 10
Single choice

Splunk Parses data into individual events, extracts time, and assigns metadata.

A.

False

B.

True

Showing 10 of 244 questions · Unlock the full set