QCM
QCM
QCM
Field?
A. user
B. source
C. location
D. sourceIp
B. Save the search as a dashboard panel for each dashboard that needs the data.
C. Save the search as a scheduled alert and use it in multiple dashboards as needed.
D. Export the results of the search to an XML file and use the file as the basis of the
dashboards.
What does the following specified time range do? earliest=-
72h@h latest=@d
B. All events with a host of www3 that also have a status of 503.
C. We need more information; we cannot tell without knowing the time range.
D. Analyzes numerical fields for their ability to predict another discrete field.
Which is primary function of the timeline located under the
search bar?
C. To zoom in and zoom out, although this does not change the scale of the chart.
D. To show peaks and/or valleys in the timeline, which can indicate spikes in activity or
downtime.
A. | lookup products.csv
B. inputlookup products.csv
C. | inputlookup products.csv
D. | lookup_definition products.csv
Which statement is true about the top command?
A. The owner of the report can edit permissions from the Edit dropdown.
B. Only users with an Admin or Power User role can access other users' reports.
C. Anyone can access any reports marked as public within a shared Splunk deployment.
D. The owner of the report must clone the original report and save it to their user account.
D. To find the fields with the fewest number of values across a dataset.
What happens when a field is added to the Selected Fields list in
the fields sidebar?
A. Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field.
B. Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.
C. Custom selections will replace the Interesting Fields that Splunk populated into the list at
search time.
D. The selected field and its corresponding values will appear underneath the events in the
search results.
A. action
B. clientip
C. categoryId
D. sourcetype
A. f*il
B. *fail
C. fail*
D. *fail*
Which command automatically returns percent and count
columns when executing searches?
A. top
B. stats
C. table
D. percent
D. Lookups pull data at index time and add them to search results.
A. ג€failed passwordג€
B. ג€failed passwordג€*
A. status_code!=404
B. status_code>=400
C. status_code<=404
D. status_code>403 status_code<405
A. Index
B. Search Head
C. Indexer
D. Forwarder
A. True
B. False
Which component of Splunk is primarily responsible for saving
data?
A. Search Head
B. Heavy Forwarder
C. Indexer
D. Universal Forwarder
A. False
B. True
D. It is collection of different Splunk config files like data inputs, UI and Knowledge Object.
Three basic components of Splunk are (Choose three.):
A. Forwarders
B. Deployment Server
C. Indexer
D. Knowledge Objects
E. Index
F. Search Head
What is Splunk?
A. Splunk is a software platform to search, analyze and visualize the machine-generated data.
A. False
B. True
A. True
B. False