ExamGecko
Home Home / Splunk / SPLK-1002

Splunk SPLK-1002 Practice Test - Questions Answers, Page 9

Question list
Search
Search

Splunk alerts can be based on search that run______. (Select all that apply.)

A.
in real-time
A.
in real-time
Answers
B.
on a regular schedule
B.
on a regular schedule
Answers
C.
and have no matching events
C.
and have no matching events
Answers
Suggested answer: A, B

Explanation:

Splunk alerts can be based on searches that run in real-time or on a regular schedule3.An alert is a way to monitor your data and get notified when certain conditions are met3.You can create an alert by specifying a search and a triggering condition3.You can also specify how often you want to run the search and how you want to receive the alert notifications3.You can run the alert search in real-time, which means that it continuously monitors your data as it streams into Splunk3.Alternatively, you can run the alert search on a regular schedule, which means that it runs at fixed intervals such as every hour or every day3. Therefore, options A and B are correct, while option C is incorrect because it is not a way to run an alert search.

Which of the following about reports is/are true?

A.
Reports are knowledge objects.
A.
Reports are knowledge objects.
Answers
B.
Reports can be scheduled.
B.
Reports can be scheduled.
Answers
C.
Reports can run a script.
C.
Reports can run a script.
Answers
D.
All of the above.
D.
All of the above.
Answers
Suggested answer: D

Explanation:

A report is a way to save a search and its results in a format that you can reuse and share with others2.A report is also a type of knowledge object, which is an entity that you create to add knowledge to your data and make it easier to search and analyze2. Therefore, option A is correct.A report can be scheduled, which means that you can configure it to run at regular intervals and send the results to yourself or others via email or other methods2. Therefore, option B is correct.A report can run a script, which means that you can specify a script file to execute when the report runs and use it to perform custom actions or integrations2. Therefore, option C is correct. Therefore, option D is correct because all of the above statements are true for reports.

Select this in the fields sidebar to automatically pipe you search results to the rare command

A.
events with this field
A.
events with this field
Answers
B.
rare values
B.
rare values
Answers
C.
top values by time
C.
top values by time
Answers
D.
top values
D.
top values
Answers
Suggested answer: B

Explanation:

The fields sidebar is a panel that shows the fields that are present in your search results2.The fields sidebar has two sections: selected fields and interesting fields2.Selected fields are fields that you choose to display in your search results by clicking on them in the fields sidebar or by using the fields command2.Interesting fields are fields that appear in at least 20 percent of events or have high variability among values2.For each field in the fields sidebar, you can select one of the following options: events with this field, rare values, top values by time or top values2.If you select rare values, Splunk will automatically pipe your search results to the rare command, which shows the least common values of a field2. Therefore, option B is correct, while options A, C and D are incorrect because they do not pipe your search results to the rare command.

A report scheduled to run every 15 mins. but takes 17 mins. to complete is in danger of being_____.

A.
skipped or deferred
A.
skipped or deferred
Answers
B.
automatically accelerated
B.
automatically accelerated
Answers
C.
deleted
C.
deleted
Answers
D.
all of the above
D.
all of the above
Answers
Suggested answer: A

Explanation:

A report that is scheduled to run every 15 minutes but takes 17 minutes to complete is in danger of being skipped or deferred2.This means that Splunk may skip some scheduled runs of the report if they overlap with previous runs that are still in progress or defer them until the previous runs are finished2.This can affect the accuracy and timeliness of the report results and notifications2. Therefore, option A is correct, while options B, C and D are incorrect because they are not consequences of a report taking longer than its schedule interval.

Which of the following are valid options to speed up reports? (Select all the apply.)

A.
Edit permissions
A.
Edit permissions
Answers
B.
Edit description
B.
Edit description
Answers
C.
Edit acceleration
C.
Edit acceleration
Answers
D.
Edit schedule
D.
Edit schedule
Answers
Suggested answer: C

Explanation:

One of the valid options to speed up reports is to edit acceleration, which means that you can enable summary indexing or data model acceleration for your reports to improve their performance2.Summary indexing allows you to create reports that run over large amounts of data by storing the results of scheduled searches in a summary index and using that index for faster reporting2.Data model acceleration allows you to create reports that use data models by creating and storing summaries of the data model datasets and using them for faster reporting2. Therefore, option C is correct, while options A, B and D are incorrect because they are not options to speed up reports.

Which of the following statements are true for this search? (Select all that apply.) SEARCH: sourcetype=access* |fields action productld status

A.
is looking for all events that include the search terms: fields AND action AND productld AND status
A.
is looking for all events that include the search terms: fields AND action AND productld AND status
Answers
B.
users the table command to improve performance
B.
users the table command to improve performance
Answers
C.
limits the fields are extracted
C.
limits the fields are extracted
Answers
D.
returns a table with 3 columns
D.
returns a table with 3 columns
Answers
Suggested answer: C

Use the dedup command to _____.

A.
Rename a field in the index
A.
Rename a field in the index
Answers
B.
remove duplicate values
B.
remove duplicate values
Answers
C.
provide an additional alias for the field that can D.be used in the search criteria
C.
provide an additional alias for the field that can D.be used in the search criteria
Answers
Suggested answer: B

We can use the rename command to _____ (Select all that apply.)

A.
Change indexed fields
A.
Change indexed fields
Answers
B.
Exclude fields from our search results
B.
Exclude fields from our search results
Answers
C.
Extract new fields from our data using regular expressions
C.
Extract new fields from our data using regular expressions
Answers
D.
Give a field a new name at search time
D.
Give a field a new name at search time
Answers
Suggested answer: D

The limit attribute will___________.

A.
override default of 10
A.
override default of 10
Answers
B.
only work with top command
B.
only work with top command
Answers
C.
override default of 20
C.
override default of 20
Answers
D.
override default of 15
D.
override default of 15
Answers
Suggested answer: A

This function of the stats command allows you to identify the number of values a field has.

A.
max
A.
max
Answers
B.
distinct_count
B.
distinct_count
Answers
C.
fields
C.
fields
Answers
D.
count
D.
count
Answers
Suggested answer: D
Total 291 questions
Go to page: of 30