Splunk SPLK-1001 Practice Test - Questions Answers, Page 12
Related questions
How does Splunk determine which fields to extract from data?
A.
Splunk only extracts the most interesting data from the last 24 hours.
B.
Splunk only extracts fields users have manually specified in their data.
C.
Splunk automatically extracts any fields that generate interesting visualizations.
D.
Splunk automatically discovers many fields based on sourcetype and key/value pairs found in the data.
Which of the following file types is an option for exporting Splunk search results?
A.
PDF
B.
JSON
C.
XLS
D.
RTF
Which search string returns a filed containing the number of matching events and names that field Event Count?
A.
index=security failure | stats sum as "Event Count"
B.
index=security failure | stats count as "Event Count"
C.
index=security failure | stats count by "Event Count"
D.
index=security failure | stats dc(count) as "Event Count"
Which search would return events from the access_combined sourcetype?
A.
Sourcetype=access_combined
B.
Sourcetype=Access_Combined
C.
sourcetype=Access_Combined
D.
SOURCETYPE=access_combined
When looking at a statistics table, what is one way to drill down to see the underlying events?
A.
Creating a pivot table.
B.
Clicking on the visualizations tab.
C.
Viewing your report in a dashboard.
D.
Clicking on any field value in the table.
In the fields sidebar, what indicates that a field is numeric?
A.
A number to the right of the field name.
B.
A # symbol to the left of the field name.
C.
A lowercase n to the left of the field name.
D.
A lowercase n to the right of the field name.
What is the primary use for the rare command?
A.
To sort field values in descending order.
B.
To return only fields containing five of fewer values.
C.
To find the least common values of a field in a dataset.
D.
To find the fields with the fewest number of values across a dataset.
_______________ transforms raw data into events and distributes the results into an index.
A.
Index
B.
Search Head
C.
Indexer
D.
Forwarder
Which component of Splunk is primarily responsible for saving data?
A.
Search Head
B.
Heavy Forwarder
C.
Indexer
D.
Universal Forwarder
Question