ExamGecko
Home Home / Splunk / SPLK-1001

Splunk SPLK-1001 Practice Test - Questions Answers, Page 5

Question list
Search
Search

At index time, in which field does Splunk store the timestamp value?

A.
time
A.
time
Answers
B.
_time
B.
_time
Answers
C.
EventTime
C.
EventTime
Answers
D.
timestamp
D.
timestamp
Answers
Suggested answer: B

Which statement is true about the top command?

A.
It returns the top 10 results
A.
It returns the top 10 results
Answers
B.
It displays the output in table format
B.
It displays the output in table format
Answers
C.
It returns the count and percent columns per row
C.
It returns the count and percent columns per row
Answers
D.
All of the above
D.
All of the above
Answers
Suggested answer: D

What determines the scope of data that appears in a scheduled report?

A.
All data accessible to the User role will appear in the report.
A.
All data accessible to the User role will appear in the report.
Answers
B.
All data accessible to the owner of the report will appear in the report.
B.
All data accessible to the owner of the report will appear in the report.
Answers
C.
All data accessible to all users will appear in the report until the next time the report is run.
C.
All data accessible to all users will appear in the report until the next time the report is run.
Answers
D.
The owner of the report can configure permissions so that the report uses either the User role or the owner's profile at run time.
D.
The owner of the report can configure permissions so that the report uses either the User role or the owner's profile at run time.
Answers
Suggested answer: D

What is the main requirement for creating visualizations using the Splunk UI?

A.
Your search must transform event data into Excel file format first.
A.
Your search must transform event data into Excel file format first.
Answers
B.
Your search must transform event data into XML formatted data first.
B.
Your search must transform event data into XML formatted data first.
Answers
C.
Your search must transform event data into statistical data tables first.
C.
Your search must transform event data into statistical data tables first.
Answers
D.
Your search must transform event data into JSON formatted data first.
D.
Your search must transform event data into JSON formatted data first.
Answers
Suggested answer: C

How can another user gain access to a saved report?

A.
The owner of the report can edit permissions from the Edit dropdown
A.
The owner of the report can edit permissions from the Edit dropdown
Answers
B.
Only users with an Admin or Power User role can access other users' reports
B.
Only users with an Admin or Power User role can access other users' reports
Answers
C.
Anyone can access any reports marked as public within a shared Splunk deployment
C.
Anyone can access any reports marked as public within a shared Splunk deployment
Answers
D.
The owner of the report must clone the original report and save it to their user account
D.
The owner of the report must clone the original report and save it to their user account
Answers
Suggested answer: A

What is the primary use for the rare command1?

A.
To sort field values in descending order
A.
To sort field values in descending order
Answers
B.
To return only fields containing five or fewer values
B.
To return only fields containing five or fewer values
Answers
C.
To find the least common values of a field in a dataset
C.
To find the least common values of a field in a dataset
Answers
D.
To find the fields with the fewest number of values across a dataset
D.
To find the fields with the fewest number of values across a dataset
Answers
Suggested answer: C

What happens when a field is added to the Selected Fields list in the fields sidebar'?

A.
Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field
A.
Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field
Answers
B.
Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.
B.
Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.
Answers
C.
Custom selections will replace the Interesting Fields that Splunk populated into the list at search time
C.
Custom selections will replace the Interesting Fields that Splunk populated into the list at search time
Answers
D.
The selected field and its corresponding values will appear underneath the events in the search results
D.
The selected field and its corresponding values will appear underneath the events in the search results
Answers
Suggested answer: D

By default, which of the following is a Selected Field?

A.
action
A.
action
Answers
B.
clientip
B.
clientip
Answers
C.
categoryld
C.
categoryld
Answers
D.
sourcetype
D.
sourcetype
Answers
Suggested answer: D

According to Splunk best practices, which placement of the wildcard results in the most efficient search?

A.
f*il
A.
f*il
Answers
B.
*fail
B.
*fail
Answers
C.
fail*
C.
fail*
Answers
D.
*fail*
D.
*fail*
Answers
Suggested answer: C

Which command automatically returns percent and count columns when executing searches?

A.
top
A.
top
Answers
B.
stats
B.
stats
Answers
C.
table
C.
table
Answers
D.
percent
D.
percent
Answers
Suggested answer: A
Total 246 questions
Go to page: of 25