Splunk SPLK-1001 Practice Test - Questions Answers, Page 8
List of questions
Question 71

In automatic lookup definitions, the _____ fields are those that are not in the event data.
input
output
Suggested answer: B
Question 72

What is the correct order of steps for creating a new lookup?
Configure the lookup to run automatically
Create the lookup table
Define the lookup
2, 1, 3
1, 2, 3
2, 3, 1
3, 2, 1
Suggested answer: C
Question 73

The command shown here does witch of the following: Command: |outputlookup products.csv
Writes search results to a file named products.csv
Returns the contents of a file named products.csv
Suggested answer: A
Question 74

Which of the following are not true about lookups? (Select all that apply.)
Lookups can be time based
Search results can be used to populate a lookup tableC .Splunk DB Connect can be used to populate a lookup table from relational databases
Output from a script can be used to populate a lookup table
Lookup have a 10mg maximum size limit
Suggested answer:
Question 75

Lookups allow you to overwrite your raw event.
True
False
Suggested answer: A
Question 76

It is mandatory for the lookup file to have this for an automatic lookup to work.
Source type
At least five columns
Timestamp
Input filed
Suggested answer: D
Question 77

By default, all users have DELETE permission to ALL knowledge objects.
True
False
Suggested answer: B
Question 78

These users can create global knowledge objects. (Select all that apply.)
users
power users
administrators
Suggested answer: B, C
Question 79

All users by default have WRITE permission to ALL knowledge objects.
True
False
Suggested answer: B
Question 80

Creating Data Models:
Object ATTRIBUTES do not define ___________.
a base search for the object
fields for the object
Suggested answer: A
Question