Labour Day - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpm65

SPLK-1001 Splunk Core Certified User Questions and Answers

Questions 4

How can search results be kept longer than 7 days?

Options:

A.

By scheduling a report.

B.

By creating a link to the job.

C.

By changing the job settings.

D.

By changing the time range picker to more than 7 days.

Buy Now
Questions 5

When is an alert triggered?

Options:

A.

When Splunk encounters a syntax error in a search

B.

When a trigger action meets the predefined conditions

C.

When an event in a search matches up with a data model

D.

When results of a search meet a specifically defined condition

Buy Now
Questions 6

Which of the statements is correct regarding click and drag option in timeline?

Options:

A.

The new result after selecting the range by dragging filters the events and displays the most recent first.

B.

There is no functionality like click and drag in Splunk's timeline.

C.

Using this option executes a new query.

D.

This doesn't execute a new query

Buy Now
Questions 7

!= and NOT are same arguments.

Options:

A.

True

B.

False

Buy Now
Questions 8

Splunk Components:

Which of the following are responsible for parsing incoming data and storing data on disc?

Options:

A.

forwarders

B.

indexers

C.

search heads

Buy Now
Questions 9

Will the queries following below get the same result?

1. index=log sourcetype=error_log status !=100

2. index=log sourcetype=error_log NOT status =100

Options:

A.

Yes

B.

No

Buy Now
Questions 10

This search will return 20 results. SEARCH: error | top host limit = 20

Options:

A.

True

B.

False

Buy Now
Questions 11

By default, all users have DELETE permission to ALL knowledge objects.

Options:

A.

True

B.

False

Buy Now
Questions 12

In the fields sidebar, which character denotes alphanumeric field values?

Options:

A.

#

B.

%

C.

a

D.

a#

Buy Now
Questions 13

Portal for Splunk apps can be accessed through www.splunkbase.com

Options:

A.

False

B.

True

Buy Now
Questions 14

Put query into separate lines where | (Pipes) are used by selecting following options.

Options:

A.

CTRL + Enter

B.

Shift + Enter

C.

Space + Enter

D.

ALT + Enter

Buy Now
Questions 15

Creating Data Models:

Object ATTRIBUTES do not define ___________.

Options:

A.

a base search for the object

B.

fields for the object

Buy Now
Questions 16

These users can create global knowledge objects. (Select all that apply.)

Options:

A.

users

B.

power users

C.

administrators

Buy Now
Questions 17

There are three different search modes in Splunk (Choose three.):

Options:

A.

Automatic

B.

Smart

C.

Fast

D.

Verbose

Buy Now
Questions 18

Which of the following Splunk components typically resides on the machines where data originates?

Options:

A.

Indexer

B.

Forwarder

C.

Search head

D.

Deployment server

Buy Now
Questions 19

Which of the following is a best practice when writing a search string?

Options:

A.

Include all formatting commands before any search terms

B.

Include at least one function as this is a search requirement

C.

Include the search terms at the beginning of the search string

D.

Avoid using formatting clauses as they add too much overhead

Buy Now
Questions 20

Following are the time selection option while making search:

(Choose all that apply.)

Options:

A.

Date & Time Range

B.

Advanced

C.

Date Range

D.

Presets

E.

Relative

Buy Now
Questions 21

When sorting on multiple fields with the sort command, what delimiter can be used between the field names in the search?

Options:

A.

|

B.

$

C.

!

D.

,

Buy Now
Questions 22

Which Field/Value pair will return only events found in the index named security?

Options:

A.

index!=Security

B.

Index-security

C.

Index=Security

D.

index=Security

Buy Now
Questions 23

Clicking a SEGMENT on a chart, ________.

Options:

A.

drills down for that value

B.

highlights the field value across the chart

C.

adds the highlighted value to the search criteria

Buy Now
Questions 24

What is the correct way to use a time range specifier in the search bar so that the search looks back 2 hours?

Options:

A.

latest=-2h

B.

earliest=-2h

C.

latest=-2hour@d

D.

earliest=-2hour@d

Buy Now
Questions 25

Which statement is true about the top command?

Options:

A.

It returns the top 10 results

B.

It displays the output in table format

C.

It returns the count and percent columns per row

D.

All of the above

Buy Now
Questions 26

All users by default have WRITE permission to ALL knowledge objects.

Options:

A.

True

B.

False

Buy Now
Questions 27

Which of the following is an option after clicking an item in search results?

Options:

A.

Saving the item to a report

B.

Adding the item to the search.

C.

Adding the item to a dashboard

D.

Saving the search to a JSON file.

Buy Now
Questions 28

Splunk Components:

Which of the following are responsible for reducing search results?

Options:

A.

search heads

B.

indexers

C.

forwarders

Buy Now
Questions 29

Which command will rename action to Customer Action?

Options:

A.

| rename action = CustomerAction

B.

| rename Action as “Customer Action”

C.

| rename Action to “Customer Action”

D.

| rename action as “Customer Action”

Buy Now
Questions 30

Splunk Enterprise is used as a Scalable service in Splunk Cloud.

Options:

A.

True

B.

False

Buy Now
Questions 31

Where does Licensing meter happen?

Options:

A.

Indexer

B.

Parsing

C.

Heavy Forwarder

D.

Input

Buy Now
Questions 32

How does Splunk determine which fields to extract from data?

Options:

A.

Splunk only extracts the most interesting data from the last 24 hours.

B.

Splunk only extracts fields users have manually specified in their data.

C.

Splunk automatically extracts any fields that generate interesting visualizations.

D.

Splunk automatically discovers many fields based on sourcetype and key/value pairs found in the data.

Buy Now
Questions 33

You are able to create new Index in Data Input settings.

Options:

A.

No

B.

Yes

Buy Now
Questions 34

Beginning parentheses is automatically highlighted to guide you on the presence of complimenting

parentheses.

Options:

A.

No

B.

Yes

Buy Now
Questions 35

Which of the following are not true about lookups? (Select all that apply.)

Options:

A.

Lookups can be time based

B.

Search results can be used to populate a lookup table

C.

Splunk DB Connect can be used to populate a lookup table from relational databases

D.

Output from a script can be used to populate a lookup table

E.

Lookup have a 10mg maximum size limit

Buy Now
Questions 36

Which command automatically returns percent and count columns when executing searches?

Options:

A.

top

B.

stats

C.

table

D.

percent

Buy Now
Questions 37

Splunk shows data in __________________.

Options:

A.

ASCII Character order.

B.

Reverse chronological order.

C.

Alphanumeric order.

D.

Chronological order.

Buy Now
Questions 38

Which is not a comparison operator in Splunk

Options:

A.

<=

B.

=

C.

!=

D.

>

E.

?=

Buy Now
Questions 39

What happens when a field is added to the Selected Fields list in the fields sidebar'?

Options:

A.

Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field

B.

Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.

C.

Custom selections will replace the Interesting Fields that Splunk populated into the list at search time

D.

The selected field and its corresponding values will appear underneath the events in the search results

Buy Now
Questions 40

When is the pipe character, I, used in search strings?

Options:

A.

Before clauses. For example: stats sum(bytes) | by host

B.

Before commands. For example: | stats sum(bytes) by host

C.

Before arguments. For example: stats sum| (bytes) by host

D.

Before functions. For example: stats |sum(bytes) by host

Buy Now
Questions 41

Select the answer that displays the accurate placing of the pipe in the following search string:

index=security sourcetype=access_* status=200 stats count by price

Options:

A.

index=security sourcetype=access_* status=200 stats | count by price

B.

index=security sourcetype=access_* status=200 | stats count by price

C.

index=security sourcetype=access_* status=200 | stats count | by price

D.

index=security sourcetype=access_* | status=200 | stats count by price

Buy Now
Questions 42

Which component of Splunk let us write SPL query to find the required data?

Options:

A.

Forwarders

B.

Indexer

C.

Heavy Forwarders

D.

Search head

Buy Now
Questions 43

Which of the following is the most efficient filter for running searches in Splunk?

Options:

A.

Time

B.

Fast mode

C.

Sourcetype

D.

Selected Fields

Buy Now
Questions 44

Which of the following represents the Splunk recommended naming convention for dashboards?

Options:

A.

Description_Group_Object

B.

Group_Description_Object

C.

Group_Object_Description

D.

Object_Group_Description

Buy Now
Questions 45

Which of the following are Splunk premium enhanced solutions? (Choose three.)

Options:

A.

Splunk User Behavior Analytics (UBA)

B.

Splunk IT Service Intelligence (ITSI)

C.

Splunk Enterprise Security (ES)

D.

Splunk Analytics Security (AS)

Buy Now
Questions 46

Which search matches the events containing the terms "error" and "fail"?

Options:

A.

index=security Error Fail

B.

index=security error OR fail

C.

index=security “error failure”

D.

index=security NOT error NOT fail

Buy Now
Questions 47

What are the three main Splunk components?

Options:

A.

Search head, GPU, streamer

B.

Search head, indexer, forwarder

C.

Search head, SQL database, forwarder

D.

Search head, SSD, heavy weight agent

Buy Now
Questions 48

Uploading local files though Upload options index the file only once.

Options:

A.

No

B.

Yes

Buy Now
Questions 49

What does the values function of the stats command do?

Options:

A.

Lists all values of a given field.

B.

Lists unique values of a given field.

C.

Returns a count of unique values for a given field.

D.

Returns the number of events that match the search.

Buy Now
Questions 50

How many main user roles do you have in Splunk?

Options:

A.

2

B.

4

C.

1

D.

3

Buy Now
Questions 51

In the Fields sidebar, what does the number directly to the right of the field name indicate?

Options:

A.

The value of the field

B.

The number of values for the field

C.

The number of unique values for the field

D.

The numeric non-unique values of the field

Buy Now
Questions 52

Which of the statements are correct? (Choose three.)

Options:

A.

Zoom to selection: Narrows the time range and re-executes the search.

B.

Zoom to selection: Narrows the time range and doesn't re-executes the search.

C.

Format Timeline: Hides or shows the timeline in different views.

D.

Zoom-Out: Expands the time focus and doesn't re-executes the search.

E.

Zoom-out: Expands the time focus and re-executes the search.

Buy Now
Questions 53

This clause is used to group the output of a stats command by a specific name.

Options:

A.

Rex

B.

As

C.

List

D.

By

Buy Now
Questions 54

It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.

Options:

A.

True

B.

False

Buy Now
Questions 55

Events in Splunk are automatically segregated using data and time.

Options:

A.

Yes

B.

No

Buy Now
Questions 56

Which of the following is a Splunk search best practice?

Options:

A.

Filter as early as possible.

B.

Never specify more than one index.

C.

Include as few search terms as possible.

D.

Use wildcards to return more search results.

Buy Now
Questions 57

The stats command will create a _____________ by default.

Options:

A.

Table

B.

Report

C.

Pie chart

Buy Now
Questions 58

Which of the following searches would return only events that match the following criteria?

• Events are inside the main index

• The field status exists in the event

• The value in the status field does not equal 200

Options:

A.

index==main status!==200

B.

index=main NOT status=200

C.

index==main NOT status==200

D.

index-main status!=200

Buy Now
Questions 59

Parsing of data can happen both in HF and Indexer.

Options:

A.

Only HF

B.

No

C.

Yes

Buy Now
Questions 60

Which of the following fields is stored with the events in the index?

Options:

A.

user

B.

source

C.

location

D.

sourcelp

Buy Now
Questions 61

What user interface component allows for time selection?

Options:

A.

Time summary

B.

Time range picker

C.

Search time picker

D.

Data source time statistics

Buy Now
Questions 62

How do you add or remove fields from search results?

Options:

A.

Use field +to add and field -to remove.

B.

Use table +to add and table -to remove.

C.

Use fields +to add and fields –to remove.

D.

Use fields Plus to add and fields Minus to remove.

Buy Now
Questions 63

Every Search in Splunk is also called _____________.

Options:

A.

None of the above

B.

Job

C.

Search Only

Buy Now
Questions 64

Can you stop or pause the searching?

Options:

A.

No

B.

Yes

Buy Now
Questions 65

Which symbol is used to snap the time?

Options:

A.

@

B.

&

C.

*

D.

#

Buy Now
Questions 66

This is what Splunk uses to categorize the data that is being indexed.

Options:

A.

sourcetype

B.

index

C.

source

D.

host

Buy Now
Questions 67

In automatic lookup definitions, the _____ fields are those that are not in the event data.

Options:

A.

input

B.

output

Buy Now
Questions 68

NOT status = 100:

Options:

A.

Will display result depending on the data.

B.

Will return event where status field exist but value of that field is not 100.

C.

Will return event where status field exist but value of that field is not 100 and all events where status field

doesn't exist.

Buy Now
Questions 69

When using the top command in the following search, which of the following will be true about the results?

index="main" sourcetype="access_*" action="purchase" | top 3 statusCode by user showperc=f countfield=status_code_count

Options:

A.

The search will fail. The proper top command format is top limit=3 instead of top 3.

B.

The top three most common values in statusCode will be displayed for each user.

C.

Only the top three overall most common values in statusCode will be displayed.

D.

The percentage field will be displayed in the results.

Buy Now
Questions 70

Which of the following is a false statement about Splunk dashboards?

Options:

A.

Dashboards must have a unique dashboard ID within a permission's context.

B.

Splunk dashboards consist of one or more panels displaying data visually in a useful way.

C.

Splunk dashboards may not be directly created from search results without first creating a report.

D.

Splunk dashboard panels can be populated by reports.

Buy Now
Questions 71

Which of the following is the best way to create a report that shows the last 24 hours of events?

Options:

A.

Use earliest=-1d@d latest=@d

B.

Set a real-time search over a 24-hour window

C.

Use the time range picket to select “Yesterday”

D.

Use the time range picker to select “Last 24 hours”

Buy Now
Questions 72

What is the primary use for the rare command?

Options:

A.

To sort field values in descending order.

B.

To return only fields containing five of fewer values.

C.

To find the least common values of a field in a dataset.

D.

To find the fields with the fewest number of values across a dataset.

Buy Now
Questions 73

What must be done in order to use a lookup table in Splunk?

Options:

A.

The lookup must be configured to run automatically.

B.

The contents of the lookup file must be copied and pasted into the search bar.

C.

The lookup file must be uploaded to Splunk and a lookup definition must be created.

D.

The lookup file must be uploaded to the etc/apps/lookups folder for automatic ingestion.

Buy Now
Exam Code: SPLK-1001
Exam Name: Splunk Core Certified User
Last Update: Apr 23, 2024
Questions: 244

PDF + Testing Engine

$56  $159.99

Testing Engine

$42  $119.99
buy now SPLK-1001 testing engine

PDF (Q&A)

$35  $99.99
buy now SPLK-1001 pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 25 Apr 2024