Splunk 1/100

Splunk 1/100

Professional Development

100 Qs

quiz-placeholder

Similar activities

Hamilton College Family Quiz 2

Hamilton College Family Quiz 2

KG - Professional Development

100 Qs

Câu hỏi về Chương 6

Câu hỏi về Chương 6

Professional Development

100 Qs

Behavior Analyst Certification Quiz

Behavior Analyst Certification Quiz

Professional Development

100 Qs

Paket 7

Paket 7

Professional Development

100 Qs

Splunk 1/100

Splunk 1/100

Assessment

Quiz

Specialty

Professional Development

Practice Problem

Easy

Created by

Sebastián Gutiérrez

Used 2+ times

FREE Resource

AI

Enhance your content in a minute

Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...

100 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which search string only returns events from hostWWW3?

host=*
host=WWW3
host=WWW*
Host=WWW3

2.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

By default, how long does Splunk retain a search job?

10 Minutes
15 Minutes
1 Day
7 Days

3.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

What must be done before an automatic lookup can be created? (Choose all that apply.)

The lookup command must be use
The lookup definition must be create
The lookup file must be uploaded to Splunk.
The lookup file must be verified using the inputlookup comman

4.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which of the following Splunk components typically resides on the machines where data originates?

Indexer
Forwarder
Search head
Deployment server

5.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

What determines the scope of data that appears in a scheduled report?

All data accessible to the User role will appear in the report.
All data accessible to the owner of the report will appear in the report.
All data accessible to all users will appear in the report until the next time the report is run.
The owner of the report can configure permissions so that the report uses either the User role or the owners profile at run time.

6.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

When writing searches in Splunk, which of the following is true about Booleans?

They must be lowercase.
They must be uppercase.
They must be in quotations.
They must be in parentheses.

7.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which of the following searches would return events with failure in index netfw or warn or critical in index netops?

(index=netfw failure) AND index=netops warn OR critical
(index=netfw failure) OR (index=netops (warn OR critical))
(index=netfw failure) AND (index=netops (warn OR critical))
(index=netfw failure) OR index=netops OR (warn OR critical)

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?