Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

SPLK-1001 Splunk Core Certified User Exam Questions and Answers

Questions 4

Splunk users are assigned roles. Which of the following do roles determine?

Options:

A.

Password

B.

Port number

C.

Username

D.

Data access

Buy Now
Questions 5

Splunk automatically determines the source type for major data types.

Options:

A.

False

B.

True

Buy Now
Questions 6

Following are the time selection option while making search:

(Choose all that apply.)

Options:

A.

Date & Time Range

B.

Advanced

C.

Date Range

D.

Presets

E.

Relative

Buy Now
Questions 7

36. Lookups can be private for a user.

Options:

A.

True

B.

False

Buy Now
Questions 8

Splunk extracts fields from event data at index time and at search time.

Options:

A.

True

B.

False

Buy Now
Questions 9

When a search returns __________, you can view the results as a list.

Options:

A.

a list of events

B.

transactions

C.

statistical values

Buy Now
Questions 10

Universal forwarder is recommended for forwarding the logs to indexers.

Options:

A.

False

B.

True

Buy Now
Questions 11

What is the main requirement for creating visualizations using the Splunk UI?

Options:

A.

Your search must transform event data into Excel file format first.

B.

Your search must transform event data into XML formatted data first.

C.

Your search must transform event data into statistical data tables first.

D.

Your search must transform event data into JSON formatted data first.

Buy Now
Questions 12

Which Field/Value pair will return only events found in the index named security?

Options:

A.

Index=Security

B.

index=Security

C.

Index=security

D.

index!=Security

Buy Now
Questions 13

When saving a search directly to a dashboard panel instead of saving as a report first, which of the following is

created?

Options:

A.

Cloned panel

B.

Inline panel

C.

Report panel

D.

Prebuilt panel

Buy Now
Questions 14

When refining search results, what is the difference in the time picker between real-time and relative time ranges?

Options:

A.

Real-time searches happen instantly, while relative searches happen at a scheduled time.

B.

Real-time searches display results from a rolling time window, while relative searches display results from a set length of time.

C.

Real-time searches run constantly in the background, while relative searches only run when certain criteria are met.

D.

Real-time represents events that have happened in a set time window, while relative will display results from a rolling time window.

Buy Now
Questions 15

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

Options:

A.

host

B.

index

C.

source

D.

sourcetype

Buy Now
Questions 16

What are Splunk alerts based on?

Options:

A.

Dashboards

B.

Searches

C.

Webhooks

D.

Reports

Buy Now
Questions 17

The stats command will create a _____________ by default.

Options:

A.

Table

B.

Report

C.

Pie chart

Buy Now
Questions 18

Events in Splunk are automatically segregated using data and time.

Options:

A.

Yes

B.

No

Buy Now
Questions 19

How to make Interesting field into a selected field?

Options:

A.

Click field in field sidebar -> click YES on the pop-up dialog on upper right side -> check now field should

be visible in the list of selected fields.

B.

Not possible.

C.

Only CLI changes will enable it.

D.

Click Settings -> Find field option -> Drop down select field -> enable selected field -> check now field

should be visible in the list of selected fields.

Buy Now
Questions 20

How do you add or remove fields from search results?

Options:

A.

Use field +to add and field -to remove.

B.

Use table +to add and table -to remove.

C.

Use fields +to add and fields –to remove.

D.

Use fields Plus to add and fields Minus to remove.

Buy Now
Questions 21

In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?

Options:

A.

No events will be returned.

B.

Splunk will prompt you to specify an index.

C.

All non-indexed events to which the user has access will be returned.

D.

Events from every index searched by default to which the user has access will be returned.

Buy Now
Questions 22

What determines the scope of data that appears in a scheduled report?

Options:

A.

All data accessible to the User role will appear in the report.

B.

All data accessible to the owner of the report will appear in the report.

C.

All data accessible to all users will appear in the report until the next time the report is run.

D.

The owner of the report can configure permissions so that the report uses either the User role or the owner’s profile at run time.

Buy Now
Questions 23

Assuming a user has the capability to edit reports, which of the following are editable?

Options:

A.

Acceleration, schedule, permissions

B.

The report’s name, schedule, permissions

C.

The report’s name, acceleration, schedule

D.

The report’s name, acceleration, permissions

Buy Now
Questions 24

Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip

Options:

A.

10

B.

50

C.

100

D.

20

Buy Now
Questions 25

@ Symbol can be used in advanced time unit option.

Options:

A.

No

B.

Yes

Buy Now
Questions 26

______________ is the default web port used by Splunk.

Options:

A.

8089

B.

8000

C.

8080

D.

443

Buy Now
Questions 27

Parsing of data can happen both in HF and UF.

Options:

A.

Yes

B.

No

Buy Now
Questions 28

Splunk Enterprise is used as a Scalable service in Splunk Cloud.

Options:

A.

True

B.

False

Buy Now
Questions 29

This clause is used to group the output of a stats command by a specific name.

Options:

A.

Rex

B.

As

C.

List

D.

By

Buy Now
Questions 30

Which of the following are not true about lookups? (Select all that apply.)

Options:

A.

Lookups can be time based

B.

Search results can be used to populate a lookup table

C.

Splunk DB Connect can be used to populate a lookup table from relational databases

D.

Output from a script can be used to populate a lookup table

E.

Lookup have a 10mg maximum size limit

Buy Now
Questions 31

Which is a primary function of the timeline located under the search bar?

Options:

A.

To differentiate between structured and unstructured events in the data

B.

To sort the events returned by the search command in chronological order

C.

To zoom in and zoom out. although this does not change the scale of the chart

D.

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Buy Now
Questions 32

By default, how long does Splunk retain a search job?

Options:

A.

10 Minutes

B.

15 Minutes

C.

1 Day

D.

7 Days

Buy Now
Questions 33

Which of the following is the most efficient filter for running searches in Splunk?

Options:

A.

Time

B.

Fast mode

C.

Sourcetype

D.

Selected Fields

Buy Now
Questions 34

What is the result of the following search?

index=myindex source=c: \mydata. txt NOT error=*

Options:

A.

Only data where the error field is present and does not contain a value will be displayed.

B.

Only data with a value in the field error will be displayed.

C.

Only data that does not contain the error field will be displayed.

D.

Only data where the value of the field error does not equal an asterisk (*) will be displayed.

Buy Now
Questions 35

When viewing the results of a search, what is an Interesting Field?

Options:

A.

A field that appears in any event

B.

A field that appears in every event

C.

A field that appears in the top 10 events

D.

A field that appears in at least 20% of the events

Buy Now
Questions 36

It is not possible for a single instance of Splunk to manage the input, parsing and indexing of machine.

Options:

A.

True

B.

False

Buy Now
Questions 37

Which of the following statements about case sensitivity is true?

Options:

A.

Both field names and field values ARE case sensitive.

B.

Field names ARE case sensitive; field values are NOT.

C.

Field values ARE case sensitive; field names ARE NOT.

D.

Both field names and field values ARE NOT case sensitive.

Buy Now
Questions 38

Splunk Components:

Which of the following are responsible for reducing search results?

Options:

A.

search heads

B.

indexers

C.

forwarders

Buy Now
Questions 39

When looking at a dashboard panel that is based on a report, which of the following is true?

Options:

A.

You can modify the search string in the panel, and you can change and configure the visualization.

B.

You can modify the search string in the panel, but you cannot change and configure the visualization.

C.

You cannot modify the search string in the panel, but you can change and configure the visualization.

D.

You cannot modify the search string in the panel, and you cannot change and configure the visualization.

Buy Now
Questions 40

What are the two most efficient search filters?

Options:

A.

_time and host

B.

_time and index

C.

host and sourcetype

D.

index and sourcetype

Buy Now
Questions 41

Lookups allow you to overwrite your raw event.

Options:

A.

True

B.

False

Buy Now
Questions 42

Creating Data Models:

Fields associated with a data set are known as ______.

Options:

A.

Attributes

B.

Constraints

Buy Now
Questions 43

Splunk shows data in __________________.

Options:

A.

ASCII Character order.

B.

Reverse chronological order.

C.

Alphanumeric order.

D.

Chronological order.

Buy Now
Questions 44

How can another user gain access to a saved report?

Options:

A.

The owner of the report can edit permissions from the Edit dropdown

B.

Only users with an Admin or Power User role can access other users' reports

C.

Anyone can access any reports marked as public within a shared Splunk deployment

D.

The owner of the report must clone the original report and save it to their user account

Buy Now
Questions 45

Which of the following is an option after clicking an item in search results?

Options:

A.

Saving the item to a report

B.

Adding the item to the search.

C.

Adding the item to a dashboard

D.

Saving the search to a JSON file.

Buy Now
Questions 46

Matching search terms are highlighted.

Options:

A.

Yes

B.

No

Buy Now
Questions 47

Which of the following searches would return only events that match the following criteria?

• Events are inside the main index

• The field status exists in the event

• The value in the status field does not equal 200

Options:

A.

index==main status!==200

B.

index=main NOT status=200

C.

index==main NOT status==200

D.

index-main status!=200

Buy Now
Questions 48

Where does Licensing meter happen?

Options:

A.

Indexer

B.

Parsing

C.

Heavy Forwarder

D.

Input

Buy Now
Questions 49

When viewing results of a search job from the Activity menu, which of the following is displayed?

Options:

A.

New events based on the current time range picker

B.

The same events based on the current time range picker

C.

The same events from when the original search was executed

D.

New events in addition to the same events from the original search

Buy Now
Questions 50

NOT status = 100:

Options:

A.

Will display result depending on the data.

B.

Will return event where status field exist but value of that field is not 100.

C.

Will return event where status field exist but value of that field is not 100 and all events where status field

doesn't exist.

Buy Now
Questions 51

By default, which of the following is a Selected Field?

Options:

A.

action

B.

clientip

C.

categoryld

D.

sourcetype

Buy Now
Questions 52

What is the proper SPL terminology for specifying a particular index in a search?

Options:

A.

indexer—index_name

B.

indexer name—index_name

C.

index=index_name

D.

index name=index_name

Buy Now
Questions 53

Data sources being opened and read applies to:

Options:

A.

None of the above

B.

Indexing Phase

C.

Parsing Phase

D.

Input Phase

E.

License Metering

Buy Now
Questions 54

Snapping rounds down to the nearest specified unit.

Options:

A.

Yes

B.

No

Buy Now
Questions 55

Which of the following is the best description of Splunk Apps?

Options:

A.

Built only by Splunk employees.

B.

A collection of files.

C.

Only available for download on Splunkbase.

D.

Available on iOS and Android.

Buy Now
Questions 56

What syntax is used to link key/value pairs in search strings?

Options:

A.

action+purchase

B.

action=purchase

C.

action | purchase

D.

action equal purchase

Buy Now
Questions 57

How does Splunk determine which fields to extract from data?

Options:

A.

Splunk only extracts the most interesting data from the last 24 hours.

B.

Splunk only extracts fields users have manually specified in their data.

C.

Splunk automatically extracts any fields that generate interesting visualizations.

D.

Splunk automatically discovers many fields based on sourcetype and key/value pairs found in the data.

Buy Now
Questions 58

You can view the search result in following format (Choose three.):

Options:

A.

Table

B.

Raw

C.

Pie Chart

D.

List

Buy Now
Questions 59

Which search string matches only events with the status_code of 4:4?

Options:

A.

status_code !=404

B.

status_code>=400

C.

status_code<=404

D.

status code>403 status_code<405

Buy Now
Questions 60

Which of the following file types is an option for exporting Splunk search results?

Options:

A.

PDF

B.

JSON

C.

XLS

D.

RTF

Buy Now
Questions 61

Which of the following can be used as wildcard search in Splunk?

Options:

A.

=

B.

>

C.

!

D.

*

Buy Now
Questions 62

How are events displayed after a search is executed?

Options:

A.

In chronological order.

B.

Randomly by default.

C.

In reverse chronological order.

D.

Alphabetically according to field name.

Buy Now
Questions 63

Parsing of data can happen both in HF and Indexer.

Options:

A.

Only HF

B.

No

C.

Yes

Buy Now
Questions 64

What does the stats command do?

Options:

A.

Automatically correlates related fields

B.

Converts field values into numerical values

C.

Calculates statistics on data that matches the search criteria

D.

Analyzes numerical fields for their ability to predict another discrete field

Buy Now
Questions 65

At the time of searching the start time is 03:35:08.

Will it look back to 03:00:00 if we use -30m@h in searching?

Options:

A.

Yes

B.

No

Buy Now
Questions 66

When writing searches in Splunk, which of the following is true about Booleans?

Options:

A.

They must be lowercase.

B.

They must be uppercase.

C.

They must be in quotations.

D.

They must be in parentheses.

Buy Now
Questions 67

Which events will be returned by the following search string?

host=www3 status=503

Options:

A.

All events that either have a host of www3 or a status of 503.

B.

All events with a host of www3 that also have a status of 503

C.

We need more information: we cannot tell without knowing the time range

D.

We need more information a search cannot be run without specifying an index

Buy Now
Questions 68

Forward Option gather and forward data to indexers over a receiving port from remote machines.

Options:

A.

False

B.

True

Buy Now
Questions 69

What options do you get after selecting timeline? (Choose four.)

Options:

A.

Zoom to selection

B.

Format Timeline

C.

Deselect

D.

Delete

E.

Zoom Out

Buy Now
Questions 70

Creating Data Models:

Object ATTRIBUTES do not define ___________.

Options:

A.

a base search for the object

B.

fields for the object

Buy Now
Questions 71

When an alert action is configured to run a script, Splunk must be able to locate the script. Which is one of the directories Splunk will look in to find the script?

Options:

A.

$SPLUNK_HOME/bin/scripts

B.

$SPLUNK_HOME/etc/scripts

C.

$SPLUNK_HOME/bin/etc/scripts

D.

$SPLUNK_HOME/etc/scripts/bin

Buy Now
Questions 72

Which component of Splunk is primarily responsible for saving data?

Options:

A.

Search Head

B.

Heavy Forwarder

C.

Indexer

D.

Universal Forwarder

Buy Now
Questions 73

Which Boolean operator is implied between search terms, unless otherwise specified?

Options:

A.

OR

B.

AND

C.

NOT

D.

NAND

Buy Now
Exam Code: SPLK-1001
Exam Name: Splunk Core Certified User Exam
Last Update: May 4, 2024
Questions: 244
SPLK-1001 pdf

SPLK-1001 PDF

$28  $80
SPLK-1001 Engine

SPLK-1001 Testing Engine

$33.25  $95
SPLK-1001 PDF + Engine

SPLK-1001 PDF + Testing Engine

$45.5  $130