Pass the Splunk Splunk Core Certified User SPLK-1001 Questions and answers with CertsForce

Viewing page 1 out of 8 pages
Viewing questions 1-10 out of questions
Questions # 1:

Where does Licensing meter happen?

Options:

A.

Indexer


B.

Parsing


C.

Heavy Forwarder


D.

Input


Expert Solution
Questions # 2:

When using the top command in the following search, which of the following will be true about the results?

index="main" sourcetype="access_*" action="purchase" | top 3 statusCode by user showperc=f countfield=status_code_count

Options:

A.

The search will fail. The proper top command format is top limit=3 instead of top 3.


B.

The top three most common values in statusCode will be displayed for each user.


C.

Only the top three overall most common values in statusCode will be displayed.


D.

The percentage field will be displayed in the results.


Expert Solution
Questions # 3:

In monitor option you can select the following options in GUI.

Options:

A.

Only HTTP Event Collector (HEC) and TCP/UDP


B.

None of the above


C.

Only TCP/UDP


D.

Only Scripts


E.

Filed & Directories, HTTP Event Collector (HEC), TCP/UDP and Scripts


Expert Solution
Questions # 4:

Creating Data Models:

Fields associated with a data set are known as ______.

Options:

A.

Attributes


B.

Constraints


Expert Solution
Questions # 5:

Splunk Parses data into individual events, extracts time, and assigns metadata.

Options:

A.

False


B.

True


Expert Solution
Questions # 6:

Which search string returns a filed containing the number of matching events and names that field Event Count?

Options:

A.

index=security failure | stats sum as “Event Count”


B.

index=security failure | stats count as “Event Count”


C.

index=security failure | stats count by “Event Count”


D.

index=security failure | stats dc(count) as “Event Count”


Expert Solution
Questions # 7:

36. Lookups can be private for a user.

Options:

A.

True


B.

False


Expert Solution
Questions # 8:

Selected fields are a set of configurable fields displayed for each event.

Options:

A.

True


B.

False


Expert Solution
Questions # 9:

It is not possible for a single instance of Splunk to manage the input, parsing and indexing of machine.

Options:

A.

True


B.

False


Expert Solution
Questions # 10:

Parsing of data can happen both in HF and Indexer.

Options:

A.

Only HF


B.

No


C.

Yes


Expert Solution
Viewing page 1 out of 8 pages
Viewing questions 1-10 out of questions