ExamGecko
Home / Splunk / SPLK-1001
Ask Question

Splunk SPLK-1001 Practice Test - Questions Answers, Page 6

Question list
Search

Question 51

Report
Export
Collapse

Which of the following describes lookup files?

Lookup fields cannot be used in searches
Lookup fields cannot be used in searches
Lookups contain static data available in the index
Lookups contain static data available in the index
Lookups add more fields to results returned by a search
Lookups add more fields to results returned by a search
Lookups pull data at index time and add them to search results
Lookups pull data at index time and add them to search results
Suggested answer: B
asked 23/09/2024
Gina Diaz
33 questions

Question 52

Report
Export
Collapse

When running searches command modifiers in the search string are displayed in what color?

Red
Red
Blue
Blue
Orange
Orange
Highlighted
Highlighted
Suggested answer: B
asked 23/09/2024
Azfar khan
40 questions

Question 53

Report
Export
Collapse

How do you add or remove fields from search results?

Use field +to add and field -to remove.
Use field +to add and field -to remove.
Use table +to add and table -to remove.
Use table +to add and table -to remove.
Use fields +to add and fields –to remove.
Use fields +to add and fields –to remove.
Use fields Plus to add and fields Minus to remove.
Use fields Plus to add and fields Minus to remove.
Suggested answer: C
asked 23/09/2024
Raajhavelu Rengaraj
21 questions

Question 54

Report
Export
Collapse

What are the steps to schedule a report?

After saving the report, click Schedule.
After saving the report, click Schedule.
After saving the report, click Event Type.
After saving the report, click Event Type.
After saving the report, click Scheduling.
After saving the report, click Scheduling.
After saving the report, click Dashboard Panel.
After saving the report, click Dashboard Panel.
Suggested answer: A
asked 23/09/2024
Abbas Ali
38 questions

Question 55

Report
Export
Collapse

By default, how long does Splunk retain a search job?

10 Minutes
10 Minutes
15 Minutes
15 Minutes
1 Day
1 Day
7 Days
7 Days
Suggested answer: A
asked 23/09/2024
Karl Ranson
42 questions

Question 56

Report
Export
Collapse

Which Boolean operator is implied between search terms, unless otherwise specified?

OR
OR
AND
AND
NOT
NOT
NAND
NAND
Suggested answer: B
asked 23/09/2024
Rahul Biradavolu
41 questions

Question 57

Report
Export
Collapse

What is a primary function of a scheduled report?

Auto-detect changes in performance
Auto-detect changes in performance
Auto-generated PDF reports of overall data trends
Auto-generated PDF reports of overall data trends
Regularly scheduled archiving to keep disk space use low
Regularly scheduled archiving to keep disk space use low
Triggering an alert in your Splunk instance when certain conditions are met
Triggering an alert in your Splunk instance when certain conditions are met
Suggested answer: D
asked 23/09/2024
Jack de Cort
28 questions

Question 58

Report
Export
Collapse

When sorting on multiple fields with the sort command, what delimiter can be used between the field names in the search?

|
|
$
$
!
!
,
,
Suggested answer: D
asked 23/09/2024
Ruggero Pozza
38 questions

Question 59

Report
Export
Collapse

Which search string is the most efficient?

"failed password"
"failed password"
''failed password"*
''failed password"*
index=* "failed password"
index=* "failed password"
index=security "failed password"
index=security "failed password"
Suggested answer: D
asked 23/09/2024
Dominic Lugg
44 questions

Question 60

Report
Export
Collapse

Which search string matches only events with the status_code of 4:4?

status_code !=404
status_code !=404
status_code>=400
status_code>=400
status_code<=404
status_code<=404
status code>403 status_code<405
status code>403 status_code<405
Suggested answer: D
asked 23/09/2024
Quoc Nguyen
43 questions
Total 246 questions
Go to page: of 25