Splunk SPLK-1001 Practice Test - Questions Answers, Page 23
List of questions
Question 221
What is the default lifetime of every Splunk search job?
Question 222
Which search will return the 15 least common field values for the dest_ip field?
Question 223
When is an alert triggered?
Question 224
What are the three main Splunk components?
Question 225
Which statement describes field discovery at search time?
Question 226
Which Field/Value pair will return only events found in the index named security?
Question 227
Which of the following searches would return only events that match the following criteria?
β’ Events are inside the main index
β’ The field status exists in the event
β’ The value in the status field does not equal 200
Question 228
Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip
Question 229
Which Field/Value pair will return only events found in the index named security?
Question 230
How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?
Question