ExamGecko
Home Home / Splunk / SPLK-1001

Splunk SPLK-1001 Practice Test - Questions Answers, Page 11

Question list
Search
Search

Which time range picker configuration would return real-time events for the past 30 seconds?

A.
Preset - Relative: 30-seconds ago
A.
Preset - Relative: 30-seconds ago
Answers
B.
Relative - Earliest: 30-seconds ago, Latest: Now
B.
Relative - Earliest: 30-seconds ago, Latest: Now
Answers
C.
Real-time - Earliest: 30-seconds ago, Latest: Now
C.
Real-time - Earliest: 30-seconds ago, Latest: Now
Answers
D.
Advanced - Earliest: 30-seconds ago, Latest: Now
D.
Advanced - Earliest: 30-seconds ago, Latest: Now
Answers
Suggested answer: C

What is one benefit of creating dashboard panels from reports?

A.
Any newly created dashboard will include that report.
A.
Any newly created dashboard will include that report.
Answers
B.
There are no benefits to creating dashboard panels from reports.
B.
There are no benefits to creating dashboard panels from reports.
Answers
C.
It makes the dashboard more efficient because it only has to run one search string.
C.
It makes the dashboard more efficient because it only has to run one search string.
Answers
D.
Any change to the underlying report will affect every dashboard that utilizes that report.
D.
Any change to the underlying report will affect every dashboard that utilizes that report.
Answers
Suggested answer: C

Which of the following statements about case sensitivity is true?

A.
Both field names and field values ARE case sensitive.
A.
Both field names and field values ARE case sensitive.
Answers
B.
Field names ARE case sensitive; field values are NOT.
B.
Field names ARE case sensitive; field values are NOT.
Answers
C.
Field values ARE case sensitive; field names ARE NOT.
C.
Field values ARE case sensitive; field names ARE NOT.
Answers
D.
Both field names and field values ARE NOT case sensitive.
D.
Both field names and field values ARE NOT case sensitive.
Answers
Suggested answer: B

What does the rare command do?

A.
Returns the least common field values of a given field in the results.
A.
Returns the least common field values of a given field in the results.
Answers
B.
Returns the most common field values of a given field in the results.
B.
Returns the most common field values of a given field in the results.
Answers
C.
Returns the top 10 field values of a given field in the results.
C.
Returns the top 10 field values of a given field in the results.
Answers
D.
Returns the lowest 10 field values of a given field in the results.
D.
Returns the lowest 10 field values of a given field in the results.
Answers
Suggested answer: A

Which Boolean operator is always implied between two search terms, unless otherwise specified?

A.
OR
A.
OR
Answers
B.
NOT
B.
NOT
Answers
C.
AND
C.
AND
Answers
D.
XOR
D.
XOR
Answers
Suggested answer: C

What does the values function of the stats command do?

A.
Lists all values of a given field.
A.
Lists all values of a given field.
Answers
B.
Lists unique values of a given field.
B.
Lists unique values of a given field.
Answers
C.
Returns a count of unique values for a given field.
C.
Returns a count of unique values for a given field.
Answers
D.
Returns the number of events that match the search.
D.
Returns the number of events that match the search.
Answers
Suggested answer: B

A field exists in search results, but isn't being displayed in the fields sidebar. How can it be added to the fields sidebar?

A.
Click All Fields and select the field to add it to Selected Fields.
A.
Click All Fields and select the field to add it to Selected Fields.
Answers
B.
Click Interesting Fields and select the field to add it to Selected Fields.
B.
Click Interesting Fields and select the field to add it to Selected Fields.
Answers
C.
Click Selected Fields and select the field to add it to Interesting Fields.
C.
Click Selected Fields and select the field to add it to Interesting Fields.
Answers
D.
This scenario isn't possible because all fields returned from a search always appear in the fields sidebar.
D.
This scenario isn't possible because all fields returned from a search always appear in the fields sidebar.
Answers
Suggested answer: A

In the fields sidebar, which character denotes alphanumeric field values?

A.
#
A.
#
Answers
B.
%
B.
%
Answers
C.
a
C.
a
Answers
D.
a#
D.
a#
Answers
Suggested answer: B

Which of the following searches will return results where fail, 400, and error exist in every event?

A.
error AND (fail AND 400)
A.
error AND (fail AND 400)
Answers
B.
error OR (fail and 400)
B.
error OR (fail and 400)
Answers
C.
error AND (fail OR 400)
C.
error AND (fail OR 400)
Answers
D.
error OR fail OR 400
D.
error OR fail OR 400
Answers
Suggested answer: C

Which of the following is the most efficient filter for running searches in Splunk?

A.
Time
A.
Time
Answers
B.
Fast mode
B.
Fast mode
Answers
C.
Sourcetype
C.
Sourcetype
Answers
D.
Selected Fields
D.
Selected Fields
Answers
Suggested answer: A
Total 246 questions
Go to page: of 25