Free SPLK-1001 Exam Braindumps (page: 5)

Page 4 of 62

Which search matches the events containing the terms "error" and "fail"?

  1. index=security Error Fail
  2. index=security error OR fail
  3. index=security "error failure"
  4. index=security NOT error NOT fail

Answer(s): A


Reference:

https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/Search



Which of the following is an option after clicking an item in search results?

  1. Saving the item to a report
  2. Adding the item to the search.
  3. Adding the item to a dashboard
  4. Saving the search to a JSON file.

Answer(s): A



When placed early in a search, which command is most effective at reducing search execution time?

  1. dedup
  2. rename
  3. sort -
  4. fields +

Answer(s): A



In the Splunk interface, the list of alerts can be filtered based on which characteristics?

  1. App, Owner, Severity, and Type
  2. App, Owner, Priority, and Status
  3. App, Dashboard, Severity, and Type
  4. App, Time Window, Type, and Severity

Answer(s): D






Post your Comments and Discuss Splunk® SPLK-1001 exam with other Community members:

SPLK-1001 Discussions & Posts