Free Splunk® SPLK-1001 Exam Questions (page: 19)

Which statement is true about Splunk alerts?

  1. Alerts are based on searches that are either run on a scheduled interval or in real-time.
  2. Alerts are based on searches and when triggered will only send an email notification.
  3. Alerts are based on searches and require cron to run on scheduled interval.
  4. Alerts are based on searches that are run exclusively as real-time.

Answer(s): A



What can be configured using the Edit Job Settings menu?

  1. Export the results to CSV format
  2. Add the Job results to a dashboard
  3. Schedule the Job to re-run in 10 minutes
  4. Change Job Lifetime from 10 minutes to 7 days.

Answer(s): D



Which command is used to validate a lookup file?

  1. | lookup products.csv
  2. inputlookup products.csv
  3. I inputlookup products.csv
  4. | lookup definition products.csv

Answer(s): C



Which stats command function provides a count of how many unique values exist for a given field in the result set?

  1. dc(field)
  2. count(field)
  3. count-by(field)
  4. distinct-count(field)

Answer(s): A



What user interface component allows for time selection?

  1. Time summary
  2. Time range picker
  3. Search time picker
  4. Data source time statistics

Answer(s): B



When an alert action is configured to run a script, Splunk must be able to locate the script.
Which is one of the directories Splunk will look in to find the script?

  1. $SPLUNK_HOME/bin/scripts
  2. $SPLUNK_HOME/etc/scripts
  3. $SPLUNK_HOME/bin/etc/scripts
  4. $SPLUNK_HOME/etc/scripts/bin

Answer(s): A



When editing a dashboard, which of the following are possible options? (select all that apply)

  1. Add an output.
  2. Export a dashboard panel.
  3. Modify the chart type displayed in a dashboard panel.
  4. Drag a dashboard panel to a different location on the dashboard.

Answer(s): D



Which of the following index searches would provide the most efficient search performance?

  1. index=*
  2. index=web OR index=s*
  3. (index=web OR index=sales)
  4. *index=sales AND index=web*

Answer(s): C



Viewing page 19 of 32



Post your Comments and Discuss Splunk® SPLK-1001 exam prep with other Community members:

SPLK-1001 Exam Discussions & Posts