Labour Day Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

SPLK-1001 Sample Questions Answers

Questions 4

What is the purpose of using a by clause with the stats command?

Options:

A.

To group the results by one or more fields.

B.

To compute numerical statistics on each field.

C.

To specify how the values in a list are delimited.

D.

To partition the input data based on the split-by fields.

Buy Now
Questions 5

This function of the stats command allows you to return the sample standard deviation of a field.

Options:

A.

stdev

B.

dev

C.

count deviation

D.

by standarddev

Buy Now
Questions 6

Which is a primary function of the timeline located under the search bar?

Options:

A.

To differentiate between structured and unstructured events in the data

B.

To sort the events returned by the search command in chronological order

C.

To zoom in and zoom out. although this does not change the scale of the chart

D.

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Buy Now
Questions 7

Splunk indexes the data on the basis of timestamps.

Options:

A.

True

B.

False

Buy Now
Questions 8

Which of the following are Splunk premium enhanced solutions? (Choose three.)

Options:

A.

Splunk User Behavior Analytics (UBA)

B.

Splunk IT Service Intelligence (ITSI)

C.

Splunk Enterprise Security (ES)

D.

Splunk Analytics Security (AS)

Buy Now
Questions 9

What user interface component allows for time selection?

Options:

A.

Time summary

B.

Time range picker

C.

Search time picker

D.

Data source time statistics

Buy Now
Questions 10

What is the correct syntax to count the number of events containing a vendor_action field?

Options:

A.

count stats vendor_action

B.

count stats (vendor_action)

C.

stats count (vendor_action)

D.

stats vendor_action (count)

Buy Now
Questions 11

In automatic lookup definitions, the _____ fields are those that are not in the event data.

Options:

A.

input

B.

output

Buy Now
Questions 12

When running searches command modifiers in the search string are displayed in what color?

Options:

A.

Red

B.

Blue

C.

Orange

D.

Highlighted

Buy Now
Questions 13

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

Options:

A.

host

B.

index

C.

source

D.

sourcetype

Buy Now
Questions 14

Matching search terms are highlighted.

Options:

A.

Yes

B.

No

Buy Now
Questions 15

Keywords are highlighted when you mouse over search results and you can click this search result to (Choose three.):

Options:

A.

Open new search.

B.

Exclude the item from search.

C.

None of the above.

D.

Add the item to search

Buy Now
Questions 16

In the Search and Reporting app, which is a default selected field?

Options:

A.

index

B.

action

C.

_time

D.

host

Buy Now
Questions 17

This search will return 20 results. SEARCH: error | top host limit = 20

Options:

A.

True

B.

False

Buy Now
Questions 18

Three basic components of Splunk are (Choose three.):

Options:

A.

Forwarders

B.

Deployment Server

C.

Indexer

D.

Knowledge Objects

E.

Index

F.

Search Head

Buy Now
Questions 19

By default, all users have DELETE permission to ALL knowledge objects.

Options:

A.

True

B.

False

Buy Now
Questions 20

36. Lookups can be private for a user.

Options:

A.

True

B.

False

Buy Now
Questions 21

Monitor option in Add Data provides _______________.

Options:

A.

Only continuous monitoring.

B.

Only One-time monitoring.

C.

None of the above.

D.

Both One-time and continuous monitoring

Buy Now
Questions 22

Splunk index time process can be broken down into __________ phases.

Options:

A.

3

B.

2

C.

4

D.

1

Buy Now
Questions 23

@ Symbol can be used in advanced time unit option.

Options:

A.

No

B.

Yes

Buy Now
Questions 24

What is the main requirement for creating visualizations using the Splunk UI?

Options:

A.

Your search must transform event data into Excel file format first.

B.

Your search must transform event data into XML formatted data first.

C.

Your search must transform event data into statistical data tables first.

D.

Your search must transform event data into JSON formatted data first.

Buy Now
Questions 25

!= and NOT are same arguments.

Options:

A.

True

B.

False

Buy Now
Questions 26

When using the top command in the following search, which of the following will be true about the results?

index="main" sourcetype="access_*" action="purchase" | top 3 statusCode by user showperc=f countfield=status_code_count

Options:

A.

The search will fail. The proper top command format is top limit=3 instead of top 3.

B.

The top three most common values in statusCode will be displayed for each user.

C.

Only the top three overall most common values in statusCode will be displayed.

D.

The percentage field will be displayed in the results.

Buy Now
Questions 27

Can you stop or pause the searching?

Options:

A.

No

B.

Yes

Buy Now
Questions 28

Which of the following commands will show the maximum bytes?

Options:

A.

sourcetype=access_* | maximum totals by bytes

B.

sourcetype=access_* | avg (bytes)

C.

sourcetype=access_* | stats max(bytes)

D.

sourcetype=access_* | max(bytes)

Buy Now
Questions 29

Search Assistant is enabled by default in the SPL editor with compact settings.

Options:

A.

No

B.

Yes

Buy Now
Questions 30

What is Search Assistant in Splunk?

Options:

A.

It is only available to Admins.

B.

Such feature does not exist in Splunk.

C.

Shows options to complete the search string

Buy Now
Questions 31

What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?

Options:

A.

the_questionnaire _pedia

B.

the_questionnaire pedia

C.

the_questionnaire_pedia

D.

the_questionnaire Pedia

Buy Now
Questions 32

What is a suggested Splunk best practice for naming reports?

Options:

A.

Reports are best named using many numbers so they can be more easily sorted.

B.

Use a consistent naming convention so they are easily separated by characteristics such as group and object.

C.

Name reports as uniquely as possible with no overlap to differentiate them from one another.

D.

Any naming convention is fine as long as you keep an external spreadsheet to keep track.

Buy Now
Questions 33

Splunk users are assigned roles. Which of the following do roles determine?

Options:

A.

Password

B.

Port number

C.

Username

D.

Data access

Buy Now
Questions 34

What are the three main Splunk components?

Options:

A.

Search head, GPU, streamer

B.

Search head, indexer, forwarder

C.

Search head, SQL database, forwarder

D.

Search head, SSD, heavy weight agent

Buy Now
Questions 35

When looking at a dashboard panel that is based on a report, which of the following is true?

Options:

A.

You can modify the search string in the panel, and you can change and configure the visualization.

B.

You can modify the search string in the panel, but you cannot change and configure the visualization.

C.

You cannot modify the search string in the panel, but you can change and configure the visualization.

D.

You cannot modify the search string in the panel, and you cannot change and configure the visualization.

Buy Now
Questions 36

Data summary button just below the search bar gives you the following (Choose three.):

Options:

A.

Hosts

B.

Sourcetypes

C.

Sources

D.

Indexes

Buy Now
Questions 37

Which of the following searches will show the number of categoryld used by each host?

Options:

A.

Sourcetype=access_* |sum bytes by host

B.

Sourcetype=access_* |stats sum(categorylD) by host

C.

Sourcetype=access_* |sum(bytes) by host

D.

Sourcetype=access_* |stats sum by host

Buy Now
Questions 38

Which all time unit abbreviations can you include in Advanced time range picker? (Choose seven.)

Options:

A.

h

B.

day

C.

mon

D.

yr

E.

y

F.

w

G.

week

Buy Now
Questions 39

Will the queries following below get the same result?

1. index=log sourcetype=error_log status !=100

2. index=log sourcetype=error_log NOT status =100

Options:

A.

Yes

B.

No

Buy Now
Questions 40

According to Splunk best practices, which placement of the wildcard results in the most efficient search?

Options:

A.

f*il

B.

*fail

C.

fail*

D.

*fail*

Buy Now
Questions 41

Which search string matches only events with the status_code of 4:4?

Options:

A.

status_code !=404

B.

status_code>=400

C.

status_code<=404

D.

status code>403 status_code<405

Buy Now
Questions 42

What type of search can be saved as a report?

Options:

A.

Any search can be saved as a report

B.

Only searches that generate visualizations

C.

Only searches containing a transforming command

D.

Only searches that generate statistics or visualizations

Buy Now
Questions 43

Splunk internal fields contains general information about events and starts from underscore i.e. _ .

Options:

A.

True

B.

False

Buy Now
Questions 44

What will always appear in the Selected Fields list?

Options:

A.

index

B.

action

C.

clientip

D.

sourcetype

Buy Now
Questions 45

Parsing of data can happen both in HF and Indexer.

Options:

A.

Only HF

B.

No

C.

Yes

Buy Now
Questions 46

What does the rare command do?

Options:

A.

Returns the least common field values of a given field in the results.

B.

Returns the most common field values of a given field in the results.

C.

Returns the top 10 field values of a given field in the results.

D.

Returns the lowest 10 field values of a given field in the results.

Buy Now
Questions 47

You can view the search result in following format (Choose three.):

Options:

A.

Table

B.

Raw

C.

Pie Chart

D.

List

Buy Now
Questions 48

Creating Data Models:

Fields associated with a data set are known as ______.

Options:

A.

Attributes

B.

Constraints

Buy Now
Questions 49

It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.

Options:

A.

True

B.

False

Buy Now
Questions 50

How can results from a specified static lookup file be displayed?

Options:

A.

lookup command

B.

inputlookup command

C.

Settings > Lookups > Input

D.

Settings > Lookups > Upload

Buy Now
Questions 51

Universal forwarder is recommended for forwarding the logs to indexers.

Options:

A.

False

B.

True

Buy Now
Questions 52

A field exists in search results, but isn’t being displayed in the fields sidebar. How can it be added to the fields sidebar?

Options:

A.

Click All Fields and select the field to add it to Selected Fields.

B.

Click Interesting Fields and select the field to add it to Selected Fields.

C.

Click Selected Fields and select the field to add it to Interesting Fields.

D.

This scenario isn’t possible because all fields returned from a search always appear in the fields sidebar.

Buy Now
Questions 53

What happens when a field is added to the Selected Fields list in the fields sidebar'?

Options:

A.

Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field

B.

Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.

C.

Custom selections will replace the Interesting Fields that Splunk populated into the list at search time

D.

The selected field and its corresponding values will appear underneath the events in the search results

Buy Now
Questions 54

Which of the following reports is available in the Fields window?

Options:

A.

Top values by time

B.

Rare values by time

C.

Events with top value fields

D.

Events with rare value fields

Buy Now
Questions 55

What does the stats command do?

Options:

A.

Automatically correlates related fields

B.

Converts field values into numerical values

C.

Calculates statistics on data that matches the search criteria

D.

Analyzes numerical fields for their ability to predict another discrete field

Buy Now
Questions 56

Which of the following is the recommended way to create multiple dashboards displaying data from the same search?

Options:

A.

Save the search as a report and use it in multiple dashboards as needed

B.

Save the search as a dashboard panel for each dashboard that needs the data

C.

Save the search as a scheduled alert and use it in multiple dashboards as needed

D.

Export the results of the search to an XML file and use the file as the basis of the dashboards

Buy Now
Questions 57

Which of the following is the most efficient filter for running searches in Splunk?

Options:

A.

Time

B.

Fast mode

C.

Sourcetype

D.

Selected Fields

Buy Now
Questions 58

Which of the following can be used as wildcard search in Splunk?

Options:

A.

=

B.

>

C.

!

D.

*

Buy Now
Questions 59

Which search would return events from the access_combined sourcetype?

Options:

A.

Sourcetype=access_combined

B.

Sourcetype=Access_Combined

C.

sourcetype=Access_Combined

D.

SOURCETYPE=access_combined

Buy Now
Questions 60

When viewing the results of a search, what is an Interesting Field?

Options:

A.

A field that appears in any event

B.

A field that appears in every event

C.

A field that appears in the top 10 events

D.

A field that appears in at least 20% of the events

Buy Now
Questions 61

Which Boolean operator is implied between search terms, unless otherwise specified?

Options:

A.

OR

B.

AND

C.

NOT

D.

NAND

Buy Now
Questions 62

What is the default lifetime of every Splunk search job?

Options:

A.

All search jobs are saved for 10 days

B.

All search jobs are saved for 10 hours

C.

All search jobs are saved for 10 weeks

D.

All search jobs are saved for 10 minutes

Buy Now
Questions 63

Which component of Splunk let us write SPL query to find the required data?

Options:

A.

Forwarders

B.

Indexer

C.

Heavy Forwarders

D.

Search head

Buy Now
Questions 64

How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?

Options:

A.

5 minutes

B.

1 minute

C.

10 minutes

D.

60 minutes

Buy Now
Questions 65

By default search results are not returned in ________ order.

Options:

A.

Chronological

B.

Reverser chronological

C.

ASCIE

D.

Alphabetical

Buy Now
Questions 66

Which stats command function provides a count of how many unique values exist for a given field in the result set?

Options:

A.

dc(field)

B.

count(field)

C.

count-by(field)

D.

distinct-count(field)

Buy Now
Questions 67

Splunk Components:

Which of the following are responsible for reducing search results?

Options:

A.

search heads

B.

indexers

C.

forwarders

Buy Now
Questions 68

Which of the following is a false statement about Splunk dashboards?

Options:

A.

Dashboards must have a unique dashboard ID within a permission's context.

B.

Splunk dashboards consist of one or more panels displaying data visually in a useful way.

C.

Splunk dashboards may not be directly created from search results without first creating a report.

D.

Splunk dashboard panels can be populated by reports.

Buy Now
Questions 69

What syntax is used to link key/value pairs in search strings?

Options:

A.

Parentheses

B.

@ or # symbols

C.

Quotation marks

D.

Relational operators such as =, <, or >

Buy Now
Questions 70

Field values are case sensitive.

Options:

A.

True

B.

False

Buy Now
Questions 71

When looking at a statistics table, what is one way to drill down to see the underlying events?

Options:

A.

Creating a pivot table.

B.

Clicking on the visualizations tab.

C.

Viewing your report in a dashboard.

D.

Clicking on any field value in the table.

Buy Now
Questions 72

Which of the following searches would return events with failure in index netfw or warn or critical in index netops?

Options:

A.

(index=netfw failure) AND index=netops warn OR critical

B.

(index=netfw failure) OR (index=netops (warn OR critical))

C.

(index=netfw failure) AND (index=netops (warn OR critical))

D.

(index=netfw failure) OR index=netops OR (warn OR critical)

Buy Now
Questions 73

Which search will return only events containing the word “error” and display the results as a table that includes

the fields named action, src, and dest?

Options:

A.

error | table action, src, dest

B.

error | tabular action, src, dest

C.

error | stats table action, src, dest

D.

error | table column=action column=src column=dest

Buy Now
Exam Code: SPLK-1001
Exam Name: Splunk Core Certified User
Last Update: May 2, 2024
Questions: 244
$64  $159.99
$48  $119.99
$40  $99.99
buy now SPLK-1001