New Year Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

SPLK-1001 Questions and Answers

Question # 6

Which of the following file types is an option for exporting Splunk search results?

A.

PDF

B.

JSON

C.

XLS

D.

RTF

Full Access
Question # 7

Splunk index time process can be broken down into __________ phases.

A.

3

B.

2

C.

4

D.

1

Full Access
Question # 8

Which of the following is a Splunk search best practice?

A.

Filter as early as possible.

B.

Never specify more than one index.

C.

Include as few search terms as possible.

D.

Use wildcards to return more search results.

Full Access
Question # 9

What are Splunk alerts based on?

A.

Dashboards

B.

Searches

C.

Webhooks

D.

Reports

Full Access
Question # 10

Fields are searchable key value pairs in your event data.

A.

True

B.

False

Full Access
Question # 11

What type of search can be saved as a report?

A.

Any search can be saved as a report

B.

Only searches that generate visualizations

C.

Only searches containing a transforming command

D.

Only searches that generate statistics or visualizations

Full Access
Question # 12

When writing searches in Splunk, which of the following is true about Booleans?

A.

They must be lowercase.

B.

They must be uppercase.

C.

They must be in quotations.

D.

They must be in parentheses.

Full Access
Question # 13

When an alert action is configured to run a script, Splunk must be able to locate the script. Which is one of the directories Splunk will look in to find the script?

A.

$SPLUNK_HOME/bin/scripts

B.

$SPLUNK_HOME/etc/scripts

C.

$SPLUNK_HOME/bin/etc/scripts

D.

$SPLUNK_HOME/etc/scripts/bin

Full Access
Question # 14

Use this command to use lookup fields in a search and see the lookup fields in the field sidebar.

A.

inputlookup

B.

lookup

Full Access
Question # 15

36. Lookups can be private for a user.

A.

True

B.

False

Full Access
Question # 16

Zoom Out and Zoom to Selection re-executes the search.

A.

No

B.

Yes

Full Access
Question # 17

How can another user gain access to a saved report?

A.

The owner of the report can edit permissions from the Edit dropdown

B.

Only users with an Admin or Power User role can access other users' reports

C.

Anyone can access any reports marked as public within a shared Splunk deployment

D.

The owner of the report must clone the original report and save it to their user account

Full Access
Question # 18

Which search will return the 15 least common field values for the dest_ip field?

A.

sourcetype=firewall | rare num=15 dest_ip

B.

sourcetype=firewall | rare last=15 dest_ip

C.

sourcetype=firewall | rare count=15 dest_ip

D.

sourcetype=firewall | rare limit=15 dest_ip

Full Access
Question # 19

In the Search and Reporting app, which is a default selected field?

A.

index

B.

action

C.

_time

D.

host

Full Access
Question # 20

Prefix wildcards might cause performance issues.

A.

False

B.

True

Full Access
Question # 21

This search will return 20 results. SEARCH: error | top host limit = 20

A.

True

B.

False

Full Access
Question # 22

Selected fields are a set of configurable fields displayed for each event.

A.

True

B.

False

Full Access
Question # 23

Which is a primary function of the timeline located under the search bar?

A.

To differentiate between structured and unstructured events in the data

B.

To sort the events returned by the search command in chronological order

C.

To zoom in and zoom out. although this does not change the scale of the chart

D.

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Full Access
Question # 24

Portal for Splunk apps can be accessed through www.splunkbase.com

A.

False

B.

True

Full Access
Question # 25

Which of the following Splunk components typically resides on the machines where data originates?

A.

Indexer

B.

Forwarder

C.

Search head

D.

Deployment server

Full Access
Question # 26

When displaying results of a search, which of the following is true about line charts?

A.

Line charts are optimal for single and multiple series.

B.

Line charts are optimal for single series when using Fast mode.

C.

Line charts are optimal for multiple series with 3 or more columns.

D.

Line charts are optimal for multiseries searches with at least 2 or more columns.

Full Access
Question # 27

Splunk extracts fields from event data at index time and at search time.

A.

True

B.

False

Full Access
Question # 28

This is what Splunk uses to categorize the data that is being indexed.

A.

sourcetype

B.

index

C.

source

D.

host

Full Access
Question # 29

Which Field/Value pair will return only events found in the index named security?

A.

Index=Security

B.

index=Security

C.

Index=security

D.

index!=Security

Full Access
Question # 30

Which symbol is used to snap the time?

A.

@

B.

&

C.

*

D.

#

Full Access
Question # 31

Which all time unit abbreviations can you include in Advanced time range picker? (Choose seven.)

A.

h

B.

day

C.

mon

D.

yr

E.

y

F.

w

G.

week

Full Access
Question # 32

Select the best options for "search best practices" in Splunk:

(Choose five.)

A.

Select the time range always.

B.

Try to specify index values.

C.

Include as many search terms as possible.

D.

Never select time range.

E.

Try to use * with every search term.

F.

Inclusion is generally better than exclusion.

G.

Try to keep specific search terms.

Full Access
Question # 33

In the Search and Reporting app, which tab displays timecharts and bar charts?

A.

Events

B.

Patterns

C.

Statistics

D.

Visualization

Full Access
Question # 34

How many main user roles do you have in Splunk?

A.

2

B.

4

C.

1

D.

3

Full Access
Question # 35

@ Symbol can be used in advanced time unit option.

A.

No

B.

Yes

Full Access
Question # 36

What is a quick, comprehensive way to learn what data is present in a Splunk deployment?

A.

Review Splunk reports

B.

Run ./splunk show

C.

Click Data Summary in Splunk Web

D.

Search index=* sourcetype=* host=*

Full Access
Question # 37

Events in Splunk are automatically segregated using data and time.

A.

Yes

B.

No

Full Access
Question # 38

What does the values function of the stats command do?

A.

Lists all values of a given field.

B.

Lists unique values of a given field.

C.

Returns a count of unique values for a given field.

D.

Returns the number of events that match the search.

Full Access
Question # 39

Which command is used to validate a lookup file?

A.

| lookup products.csv

B.

inputlookup products.csv

C.

I inputlookup products.csv

D.

| lookup definition products.csv

Full Access
Question # 40

Which of the following is the best way to create a report that shows the last 24 hours of events?

A.

Use earliest=-1d@d latest=@d

B.

Set a real-time search over a 24-hour window

C.

Use the time range picket to select “Yesterday”

D.

Use the time range picker to select “Last 24 hours”

Full Access
Question # 41

Machine data can be in structured and unstructured format.

A.

False

B.

True

Full Access
Question # 42

Splunk indexes the data on the basis of timestamps.

A.

True

B.

False

Full Access
Question # 43

There are three different search modes in Splunk (Choose three.):

A.

Automatic

B.

Smart

C.

Fast

D.

Verbose

Full Access
Question # 44

What kind of logs can Splunk Index?

A.

Only A, B

B.

Router and Switch Logs

C.

Firewall and Web Server Logs

D.

Only C

E.

Database logs

F.

All firewall, web server, database, router and switch logs

Full Access
Question # 45

Field values are case sensitive.

A.

True

B.

False

Full Access
Question # 46

A field exists in search results, but isn’t being displayed in the fields sidebar. How can it be added to the fields sidebar?

A.

Click All Fields and select the field to add it to Selected Fields.

B.

Click Interesting Fields and select the field to add it to Selected Fields.

C.

Click Selected Fields and select the field to add it to Interesting Fields.

D.

This scenario isn’t possible because all fields returned from a search always appear in the fields sidebar.

Full Access
Question # 47

Which of the following is true about user account settings and preferences?

A.

Search & Reporting is the only app that can be set as the default application.

B.

Full names can only be changed by accounts with a Power User or Admin role.

C.

Time zones are automatically updated based on the setting of the computer accessing Splunk.

D.

Full name, time zone, and default app can be defined by clicking the login name in the Splunk bar.

Full Access
Question # 48

What syntax is used to link key/value pairs in search strings?

A.

action+purchase

B.

action=purchase

C.

action | purchase

D.

action equal purchase

Full Access
Question # 49

Which of the following is a correct way to limit search results to display the 5 most common values of a field?

A.

| rare top=5

B.

| top rare=5

C.

| top limit=5

D.

| rare limit=5

Full Access
Question # 50

What is the main requirement for creating visualizations using the Splunk UI?

A.

Your search must transform event data into Excel file format first.

B.

Your search must transform event data into XML formatted data first.

C.

Your search must transform event data into statistical data tables first.

D.

Your search must transform event data into JSON formatted data first.

Full Access
Question # 51

Which of the following is a false statement about Splunk dashboards?

A.

Dashboards must have a unique dashboard ID within a permission's context.

B.

Splunk dashboards consist of one or more panels displaying data visually in a useful way.

C.

Splunk dashboards may not be directly created from search results without first creating a report.

D.

Splunk dashboard panels can be populated by reports.

Full Access
Question # 52

You can also specify a time range in the search bar. You can use the following for beginning and ending for a

time range (Choose two.):

A.

Not possible to specify time manually in Search query

B.

end=

C.

start=

D.

earliest=

E.

latest=

Full Access
Question # 53

Splunk users are assigned roles. Which of the following do roles determine?

A.

Password

B.

Port number

C.

Username

D.

Data access

Full Access
Question # 54

Which of the following is the best description of Splunk Apps?

A.

Built only by Splunk employees.

B.

A collection of files.

C.

Only available for download on Splunkbase.

D.

Available on iOS and Android.

Full Access
Question # 55

You can use the following options to specify start and end time for the query range:

A.

earliest=

B.

latest=

C.

beginning=

D.

ending=

E.

All the above

F.

Only 3rd and 4th

Full Access
Question # 56

Splunk shows data in __________________.

A.

ASCII Character order.

B.

Reverse chronological order.

C.

Alphanumeric order.

D.

Chronological order.

Full Access
Question # 57

What is the purpose of using a by clause with the stats command?

A.

To group the results by one or more fields.

B.

To compute numerical statistics on each field.

C.

To specify how the values in a list are delimited.

D.

To partition the input data based on the split-by fields.

Full Access
Question # 58

In the fields sidebar, what indicates that a field is numeric?

A.

A number to the right of the field name.

B.

A # symbol to the left of the field name.

C.

A lowercase n to the left of the field name.

D.

A lowercase n to the right of the field name.

Full Access
Question # 59

Splunk Enterprise is used as a Scalable service in Splunk Cloud.

A.

True

B.

False

Full Access
Question # 60

Matching of parentheses is a feature of Splunk Assistant.

A.

No

B.

Yes

Full Access
Question # 61

Which events will be returned by the following search string?

host=www3 status=503

A.

All events that either have a host of www3 or a status of 503.

B.

All events with a host of www3 that also have a status of 503

C.

We need more information: we cannot tell without knowing the time range

D.

We need more information a search cannot be run without specifying an index

Full Access
Question # 62

Which of the following is an option after clicking an item in search results?

A.

Saving the item to a report

B.

Adding the item to the search.

C.

Adding the item to a dashboard

D.

Saving the search to a JSON file.

Full Access
Question # 63

Log filtering/parsing can be done from _____________.

A.

Index Forwarders (IF)

B.

Universal Forwarders (UF)

C.

Super Forwarder (SF)

D.

Heavy Forwarders (HF)

Full Access
Question # 64

What is the result of the following search?

index=myindex source=c: \mydata. txt NOT error=*

A.

Only data where the error field is present and does not contain a value will be displayed.

B.

Only data with a value in the field error will be displayed.

C.

Only data that does not contain the error field will be displayed.

D.

Only data where the value of the field error does not equal an asterisk (*) will be displayed.

Full Access
Question # 65

Which of the following fields is stored with the events in the index?

A.

user

B.

source

C.

location

D.

sourcelp

Full Access
Question # 66

What can be included in the All Fields option in the sidebar?

A.

Dashboards

B.

Metadata only

C.

Non-interesting fields

D.

Field descriptions

Full Access
Question # 67

How are the results of the following search sorted?

… | sort action, —file, +bytes

A.

In descending order by action, then descending order by file, and lastly by ascending order of bytes.

B.

In ascending order by action, then descending order by file, and lastly by ascending order of bytes.

C.

In descending order by action if it exists. If not, then in descending order by file, and if both action and file do not exist, by ascending order of bytes.

D.

In ascending order by action if it exists. If not, then in descending order by file, and if both action and file do not exist, by ascending order of bytes.

Full Access
Question # 68

Data sources being opened and read applies to:

A.

None of the above

B.

Indexing Phase

C.

Parsing Phase

D.

Input Phase

E.

License Metering

Full Access
Question # 69

It is not possible for a single instance of Splunk to manage the input, parsing and indexing of machine.

A.

True

B.

False

Full Access
Question # 70

Monitor option in Add Data provides _______________.

A.

Only continuous monitoring.

B.

Only One-time monitoring.

C.

None of the above.

D.

Both One-time and continuous monitoring

Full Access
Question # 71

Select the correct option that applies to Index time processing (Choose three.).

A.

Indexing

B.

Searching

C.

Parsing

D.

Settings

E.

Input

Full Access
Question # 72

_______________ transforms raw data into events and distributes the results into an index.

A.

Index

B.

Search Head

C.

Indexer

D.

Forwarder

Full Access
Question # 73

Following are the time selection option while making search:

(Choose all that apply.)

A.

Date & Time Range

B.

Advanced

C.

Date Range

D.

Presets

E.

Relative

Full Access