Free SPLK-1001 Exam Braindumps (page: 8)

Page 3 of 32

What syntax is used to link key/value pairs in search strings?

  1. Parentheses
  2. @ or # symbols
  3. Quotation marks
  4. Relational operators such as =, <, or >

Answer(s): D



When a Splunk search generates calculated data that appears in the Statistics tab. in what formats can the results be exported?

  1. CSV, JSON, PDF
  2. CSV, XML JSON
  3. Raw Events, XML, JSON
  4. Raw Events, CSV, XML, JSON

Answer(s): D



Which of the following are functions of the stats command?

  1. count, sum, add
  2. count, sum, less
  3. sum, avg, values
  4. sum, values, table

Answer(s): C



In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?

  1. No events will be returned.
  2. Splunk will prompt you to specify an index.
  3. All non-indexed events to which the user has access will be returned.
  4. Events from every index searched by default to which the user has access will be returned.

Answer(s): D



Which search matches the events containing the terms "error" and "fail"?

  1. index=security Error Fail
  2. index=security error OR fail
  3. index=security "error failure"
  4. index=security NOT error NOT fail

Answer(s): A


Reference:

https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/Search



Which of the following is an option after clicking an item in search results?

  1. Saving the item to a report
  2. Adding the item to the search.
  3. Adding the item to a dashboard
  4. Saving the search to a JSON file.

Answer(s): A



When placed early in a search, which command is most effective at reducing search execution time?

  1. dedup
  2. rename
  3. sort -
  4. fields +

Answer(s): A



In the Splunk interface, the list of alerts can be filtered based on which characteristics?

  1. App, Owner, Severity, and Type
  2. App, Owner, Priority, and Status
  3. App, Dashboard, Severity, and Type
  4. App, Time Window, Type, and Severity

Answer(s): D






Post your Comments and Discuss Splunk® SPLK-1001 exam prep with other Community members:

SPLK-1001 Exam Discussions & Posts