Interesting fields are the fields that have at least 20% of resulting fields.
This function of the stats command allows you to return the middle-most value of field X.
Uploading local files though Upload options index the file only once.
What is the correct order of steps for creating a new lookup?
1. Configure the lookup to run automatically
2. Create the lookup table
3. Define the lookup
How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?
What is the primary use for the rare command1?
Which of the following is a metadata field assigned to every event in Splunk?
In the fields sidebar, which character denotes alphanumeric field values?
How are events displayed after a search is executed?
It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.
Which statement is true about Splunk alerts?
What can be configured using the Edit Job Settings menu?
Which events will be returned by the following search string?
host=www3 status=503
What are Splunk alerts based on?
What syntax is used to link key/value pairs in search strings?
What is the result of the following search?
index=myindex source=c: \mydata. txt NOT error=*
Which of the following are not true about lookups? (Select all that apply.)
What is one benefit of creating dashboard panels from reports?
Events in Splunk are automatically segregated using data and time.
You can view the search result in following format (Choose three.):
Which Boolean operator is always implied between two search terms, unless otherwise specified?
Which of the following are common constraints of the top command?
Data summary button just below the search bar gives you the following (Choose three.):
Can you stop or pause the searching?
All components are installed and administered in Splunk Enterprise on-premise.
What is the correct way to use a time range specifier in the search bar so that the search looks back 2 hours?
Creating Data Models:
Object ATTRIBUTES do not define ___________.
By default, which of the following fields would be listed in the fields sidebar under interesting Fields?
Fields are searchable key value pairs in your event data.
Which Field/Value pair will return only events found in the index named security?
Which symbol is used to snap the time?
Which of the following searches would return events with failure in index netfw or warn or critical in index netops?
Which of the statements is correct regarding click and drag option in timeline?
Which is not a comparison operator in Splunk
@ Symbol can be used in advanced time unit option.
When saving a search directly to a dashboard panel instead of saving as a report first, which of the following is
created?
What happens when a field is added to the Selected Fields list in the fields sidebar'?
How many main user roles do you have in Splunk?
Which of the following is the most efficient search?
Splunk shows data in __________________.
Which of the following is true about user account settings and preferences?
Which of the following is the best way to create a report that shows the last 24 hours of events?
In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?
What does the rare command do?
!= and NOT are same arguments.
It is not possible for a single instance of Splunk to manage the input, parsing and indexing of machine.
What kind of logs can Splunk Index?
In the Search and Reporting app, which tab displays timecharts and bar charts?
By default search results are not returned in ________ order.
These users can create global knowledge objects. (Select all that apply.)
Put query into separate lines where | (Pipes) are used by selecting following options.
The better way of writing search query for index is:
There are three different search modes in Splunk (Choose three.):
Splunk index time process can be broken down into __________ phases.
The new data uploaded in Splunk are shown in ________________.
Which of the following are functions of the stats command?
When is an alert triggered?
What is a suggested Splunk best practice for naming reports?
Which of the following constraints can be used with the top command?
What is the primary use for the rare command?
Selected fields are a set of configurable fields displayed for each event.
Which of the following statements about case sensitivity is true?
Which Boolean operator is implied between search terms, unless otherwise specified?
Which of the following Splunk components typically resides on the machines where data originates?
It is mandatory for the lookup file to have this for an automatic lookup to work.
Which of the following is an option after clicking an item in search results?
Which is the default app for Splunk Enterprise?
What must be done in order to use a lookup table in Splunk?
Splunk Components:
Which of the following are responsible for reducing search results?
Select the statements that are true for timeline in Splunk (Choose four.):
Matching of parentheses is a feature of Splunk Assistant.
In monitor option you can select the following options in GUI.
Search Assistant is enabled by default in the SPL editor with compact settings.