ExamGecko
Home / Splunk / SPLK-1002 / List of questions
Ask Question

Splunk SPLK-1002 Practice Test - Questions Answers, Page 9

List of questions

Question 81

Report Export Collapse

Splunk alerts can be based on search that run______. (Select all that apply.)

in real-time
in real-time
on a regular schedule
on a regular schedule
and have no matching events
and have no matching events
Suggested answer: A, B
Explanation:

Splunk alerts can be based on searches that run in real-time or on a regular schedule3.An alert is a way to monitor your data and get notified when certain conditions are met3.You can create an alert by specifying a search and a triggering condition3.You can also specify how often you want to run the search and how you want to receive the alert notifications3.You can run the alert search in real-time, which means that it continuously monitors your data as it streams into Splunk3.Alternatively, you can run the alert search on a regular schedule, which means that it runs at fixed intervals such as every hour or every day3. Therefore, options A and B are correct, while option C is incorrect because it is not a way to run an alert search.

asked 23/09/2024
EDDIE LIN
49 questions

Question 82

Report Export Collapse

Which of the following about reports is/are true?

Reports are knowledge objects.
Reports are knowledge objects.
Reports can be scheduled.
Reports can be scheduled.
Reports can run a script.
Reports can run a script.
All of the above.
All of the above.
Suggested answer: D
Explanation:

A report is a way to save a search and its results in a format that you can reuse and share with others2.A report is also a type of knowledge object, which is an entity that you create to add knowledge to your data and make it easier to search and analyze2. Therefore, option A is correct.A report can be scheduled, which means that you can configure it to run at regular intervals and send the results to yourself or others via email or other methods2. Therefore, option B is correct.A report can run a script, which means that you can specify a script file to execute when the report runs and use it to perform custom actions or integrations2. Therefore, option C is correct. Therefore, option D is correct because all of the above statements are true for reports.

asked 23/09/2024
Lucile Jeanneret
42 questions

Question 83

Report Export Collapse

Select this in the fields sidebar to automatically pipe you search results to the rare command

events with this field
events with this field
rare values
rare values
top values by time
top values by time
top values
top values
Suggested answer: B
Explanation:

The fields sidebar is a panel that shows the fields that are present in your search results2.The fields sidebar has two sections: selected fields and interesting fields2.Selected fields are fields that you choose to display in your search results by clicking on them in the fields sidebar or by using the fields command2.Interesting fields are fields that appear in at least 20 percent of events or have high variability among values2.For each field in the fields sidebar, you can select one of the following options: events with this field, rare values, top values by time or top values2.If you select rare values, Splunk will automatically pipe your search results to the rare command, which shows the least common values of a field2. Therefore, option B is correct, while options A, C and D are incorrect because they do not pipe your search results to the rare command.

asked 23/09/2024
pheangphadhu pravitpinyo
45 questions

Question 84

Report Export Collapse

A report scheduled to run every 15 mins. but takes 17 mins. to complete is in danger of being_____.

skipped or deferred
skipped or deferred
automatically accelerated
automatically accelerated
deleted
deleted
all of the above
all of the above
Suggested answer: A
Explanation:

A report that is scheduled to run every 15 minutes but takes 17 minutes to complete is in danger of being skipped or deferred2.This means that Splunk may skip some scheduled runs of the report if they overlap with previous runs that are still in progress or defer them until the previous runs are finished2.This can affect the accuracy and timeliness of the report results and notifications2. Therefore, option A is correct, while options B, C and D are incorrect because they are not consequences of a report taking longer than its schedule interval.

asked 23/09/2024
Jose Leston
47 questions

Question 85

Report Export Collapse

Which of the following are valid options to speed up reports? (Select all the apply.)

Edit permissions
Edit permissions
Edit description
Edit description
Edit acceleration
Edit acceleration
Edit schedule
Edit schedule
Suggested answer: C
Explanation:

One of the valid options to speed up reports is to edit acceleration, which means that you can enable summary indexing or data model acceleration for your reports to improve their performance2.Summary indexing allows you to create reports that run over large amounts of data by storing the results of scheduled searches in a summary index and using that index for faster reporting2.Data model acceleration allows you to create reports that use data models by creating and storing summaries of the data model datasets and using them for faster reporting2. Therefore, option C is correct, while options A, B and D are incorrect because they are not options to speed up reports.

asked 23/09/2024
rami Awad
39 questions

Question 86

Report Export Collapse

Which of the following statements are true for this search? (Select all that apply.) SEARCH: sourcetype=access* |fields action productld status

is looking for all events that include the search terms: fields AND action AND productld AND status
is looking for all events that include the search terms: fields AND action AND productld AND status
users the table command to improve performance
users the table command to improve performance
limits the fields are extracted
limits the fields are extracted
returns a table with 3 columns
returns a table with 3 columns
Suggested answer: C
asked 23/09/2024
Tolga Kesici
50 questions

Question 87

Report Export Collapse

Use the dedup command to _____.

Rename a field in the index
Rename a field in the index
remove duplicate values
remove duplicate values
provide an additional alias for the field that can D.be used in the search criteria
provide an additional alias for the field that can D.be used in the search criteria
Suggested answer: B
asked 23/09/2024
Verónica Crespo
41 questions

Question 88

Report Export Collapse

We can use the rename command to _____ (Select all that apply.)

Change indexed fields
Change indexed fields
Exclude fields from our search results
Exclude fields from our search results
Extract new fields from our data using regular expressions
Extract new fields from our data using regular expressions
Give a field a new name at search time
Give a field a new name at search time
Suggested answer: D
asked 23/09/2024
MICHELE CRISTINA DOS FELIX
39 questions

Question 89

Report Export Collapse

The limit attribute will___________.

override default of 10
override default of 10
only work with top command
only work with top command
override default of 20
override default of 20
override default of 15
override default of 15
Suggested answer: A
asked 23/09/2024
Donna Brown
44 questions

Question 90

Report Export Collapse

This function of the stats command allows you to identify the number of values a field has.

max
max
distinct_count
distinct_count
fields
fields
count
count
Suggested answer: D
asked 23/09/2024
Fahrurrazi .
29 questions
Total 299 questions
Go to page: of 30