Free SPLK-1001 Exam Braindumps (page: 29)

Page 28 of 62

Which of the following searches will return results where fail, 400, and error exist in every event?

  1. error AND (fail AND 400)
  2. error OR (fail and 400)
  3. error AND (fail OR 400)
  4. error OR fail OR 400

Answer(s): C



Which of the following is the most efficient filter for running searches in Splunk?

  1. Time
  2. Fast mode
  3. Sourcetype
  4. Selected Fields

Answer(s): A



How does Splunk determine which fields to extract from data?

  1. Splunk only extracts the most interesting data from the last 24 hours.
  2. Splunk only extracts fields users have manually specified in their data.
  3. Splunk automatically extracts any fields that generate interesting visualizations.
  4. Splunk automatically discovers many fields based on sourcetype and key/value pairs found in the data.

Answer(s): D



Which of the following file types is an option for exporting Splunk search results?

  1. PDF
  2. JSON
  3. XLS
  4. RTF

Answer(s): B






Post your Comments and Discuss Splunk® SPLK-1001 exam with other Community members:

SPLK-1001 Discussions & Posts