Search Header Logo

Splunk Core User

Authored by Ricardo Garcia

Instructional Technology

Professional Development

Splunk Core User
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

26 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

When linking key/value pairs in search strings, what syntax is used?

status-200

status | 200

status=200

status equals 200

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Out of the following queries, which search string returns a field where the number of matching events is stored, and then stored as Purchases?

index=access_combined_wcookie status=200 file="success.do" | stats sum as "Purchases"

index=access_combined_wcookie status=200 file="success.do" | stats count as "Purchases"

index=access_combined_wcookie status=200 file="success.do" | stats count by "Purchases"

index=access_combined_wcookie status=200 file="success.do" | stats dc(count) as "Purchases"

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following search strings only returns events from the source access_30day.log?

source=*

source=access_30day.log

source=access_30day.*

Source=access_30day.log

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the default retention period of a search job in Splunk by default?

10 Minutes

15 Minutes

24 Hours

7 Days

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

In a typical Splunk deployment, which of the following components is found on the machine that originates the data?

Indexer

Forwarder

Search head

Deployment server

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

When a scheduled report is run, what is the scope of the data that will be included in the report?

The report will contain all the data that the User role has access to.

Reports display all information accessible to the owner.

Until the report is run again, all data that is accessible to all users will be included in the report.

Owners have the option of configuring permissions so that a report is run using either the User role or the owner's profile.

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

The Boolean operator is just one of many search term components in Splunk. Which of the following is true about the boolean operator?

A boolean must be written in lowercase.

A boolean must be written in uppercase.

There must be quotation marks around booleans.

Parentheses are required around booleans.

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?