ExamGecko
Home Home / Splunk / SPLK-1001

Splunk SPLK-1001 Practice Test - Questions Answers, Page 8

Question list
Search
Search

In automatic lookup definitions, the _____ fields are those that are not in the event data.

A.
input
A.
input
Answers
B.
output
B.
output
Answers
Suggested answer: B

What is the correct order of steps for creating a new lookup?

A.
Configure the lookup to run automatically
A.
Configure the lookup to run automatically
Answers
B.
Create the lookup table
B.
Create the lookup table
Answers
C.
Define the lookup
C.
Define the lookup
Answers
D.
2, 1, 3
D.
2, 1, 3
Answers
E.
1, 2, 3
E.
1, 2, 3
Answers
F.
2, 3, 1
F.
2, 3, 1
Answers
G.
3, 2, 1
G.
3, 2, 1
Answers
Suggested answer: C

The command shown here does witch of the following: Command: |outputlookup products.csv

A.
Writes search results to a file named products.csv
A.
Writes search results to a file named products.csv
Answers
B.
Returns the contents of a file named products.csv
B.
Returns the contents of a file named products.csv
Answers
Suggested answer: A

Which of the following are not true about lookups? (Select all that apply.)

A.
Lookups can be time based
A.
Lookups can be time based
Answers
B.
Search results can be used to populate a lookup tableC .Splunk DB Connect can be used to populate a lookup table from relational databases
B.
Search results can be used to populate a lookup tableC .Splunk DB Connect can be used to populate a lookup table from relational databases
Answers
C.
Output from a script can be used to populate a lookup table
C.
Output from a script can be used to populate a lookup table
Answers
D.
Lookup have a 10mg maximum size limit
D.
Lookup have a 10mg maximum size limit
Answers
Suggested answer:

Lookups allow you to overwrite your raw event.

A.
True
A.
True
Answers
B.
False
B.
False
Answers
Suggested answer: A

It is mandatory for the lookup file to have this for an automatic lookup to work.

A.
Source type
A.
Source type
Answers
B.
At least five columns
B.
At least five columns
Answers
C.
Timestamp
C.
Timestamp
Answers
D.
Input filed
D.
Input filed
Answers
Suggested answer: D

By default, all users have DELETE permission to ALL knowledge objects.

A.
True
A.
True
Answers
B.
False
B.
False
Answers
Suggested answer: B

These users can create global knowledge objects. (Select all that apply.)

A.
users
A.
users
Answers
B.
power users
B.
power users
Answers
C.
administrators
C.
administrators
Answers
Suggested answer: B, C

All users by default have WRITE permission to ALL knowledge objects.

A.
True
A.
True
Answers
B.
False
B.
False
Answers
Suggested answer: B

Creating Data Models:

Object ATTRIBUTES do not define ___________.

A.
a base search for the object
A.
a base search for the object
Answers
B.
fields for the object
B.
fields for the object
Answers
Suggested answer: A
Total 246 questions
Go to page: of 25