Summer Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

SPLK-1001 Exam Dumps - Splunk Core Certified User Exam

Question # 4

When using the top command in the following search, which of the following will be true about the results?

index="main" sourcetype="access_*" action="purchase" | top 3 statusCode by user showperc=f countfield=status_code_count

A.

The search will fail. The proper top command format is top limit=3 instead of top 3.

B.

The top three most common values in statusCode will be displayed for each user.

C.

Only the top three overall most common values in statusCode will be displayed.

D.

The percentage field will be displayed in the results.

Full Access
Question # 5

Which of the following searches would return events with failure in index netfw or warn or critical in index netops?

A.

(index=netfw failure) AND index=netops warn OR critical

B.

(index=netfw failure) OR (index=netops (warn OR critical))

C.

(index=netfw failure) AND (index=netops (warn OR critical))

D.

(index=netfw failure) OR index=netops OR (warn OR critical)

Full Access
Question # 6

Keywords are highlighted when you mouse over search results and you can click this search result to (Choose three.):

A.

Open new search.

B.

Exclude the item from search.

C.

None of the above.

D.

Add the item to search

Full Access
Question # 7

Which Boolean operator is implied between search terms, unless otherwise specified?

A.

OR

B.

AND

C.

NOT

D.

NAND

Full Access
Question # 8

How do you add or remove fields from search results?

A.

Use field +to add and field -to remove.

B.

Use table +to add and table -to remove.

C.

Use fields +to add and fields –to remove.

D.

Use fields Plus to add and fields Minus to remove.

Full Access
Question # 9

What is the default lifetime of every Splunk search job?

A.

All search jobs are saved for 10 days

B.

All search jobs are saved for 10 hours

C.

All search jobs are saved for 10 weeks

D.

All search jobs are saved for 10 minutes

Full Access
Question # 10

Which is not a comparison operator in Splunk

A.

<=

B.

=

C.

!=

D.

>

E.

?=

Full Access
Question # 11

What is the correct syntax to count the number of events containing a vendor_action field?

A.

count stats vendor_action

B.

count stats (vendor_action)

C.

stats count (vendor_action)

D.

stats vendor_action (count)

Full Access
Question # 12

A collection of items containing things such as data inputs, UI elements, and knowledge objects is known as what?

A.

An app

B.

JSON

C.

A role

D.

An enhanced solution

Full Access
Question # 13

What is the result of the following search?

index=myindex source=c: \mydata. txt NOT error=*

A.

Only data where the error field is present and does not contain a value will be displayed.

B.

Only data with a value in the field error will be displayed.

C.

Only data that does not contain the error field will be displayed.

D.

Only data where the value of the field error does not equal an asterisk (*) will be displayed.

Full Access
Question # 14

Which of the following reports is available in the Fields window?

A.

Top values by time

B.

Rare values by time

C.

Events with top value fields

D.

Events with rare value fields

Full Access
Question # 15

We should use heavy forwarder for sending event-based data to Indexers.

A.

False

B.

True

Full Access
Question # 16

By default, which role contains the minimum permissions required to have write access to Splunk alerts?

A.

User

B.

Alerting

C.

Power

D.

Admin

Full Access
Question # 17

Which is a primary function of the timeline located under the search bar?

A.

To differentiate between structured and unstructured events in the data

B.

To sort the events returned by the search command in chronological order

C.

To zoom in and zoom out. although this does not change the scale of the chart

D.

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Full Access
Question # 18

Universal forwarder is recommended for forwarding the logs to indexers.

A.

False

B.

True

Full Access
Question # 19

______________ is the default web port used by Splunk.

A.

8089

B.

8000

C.

8080

D.

443

Full Access
Question # 20

How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?

A.

5 minutes

B.

1 minute

C.

10 minutes

D.

60 minutes

Full Access
Question # 21

Which of the following statements describes a search job?

A.

Once a search job begins, it cannot be stopped

B.

A search job can only be paused when less than 50% of events are returned

C.

A search job can only be stopped when less than 50% of events are returned

D.

Once a search job begins, it can be stopped or paused at any point in time

Full Access
Question # 22

Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip

A.

10

B.

50

C.

100

D.

20

Full Access
Question # 23

When viewing the results of a search, what is an Interesting Field?

A.

A field that appears in any event

B.

A field that appears in every event

C.

A field that appears in the top 10 events

D.

A field that appears in at least 20% of the events

Full Access
Question # 24

What does the rare command do?

A.

Returns the least common field values of a given field in the results.

B.

Returns the most common field values of a given field in the results.

C.

Returns the top 10 field values of a given field in the results.

D.

Returns the lowest 10 field values of a given field in the results.

Full Access
Question # 25

Which of the following can be used as wildcard search in Splunk?

A.

=

B.

>

C.

!

D.

*

Full Access
Question # 26

Which stats command function provides a count of how many unique values exist for a given field in the result set?

A.

dc(field)

B.

count(field)

C.

count-by(field)

D.

distinct-count(field)

Full Access
Question # 27

Uploading local files though Upload options index the file only once.

A.

No

B.

Yes

Full Access
Question # 28

Splunk apps are used for following (Choose three.):

A.

Designed to cater numerous use cases and empower Splunk.

B.

We can not install Splunk App.

C.

Allows multiple workspaces for different use cases/user roles.

D.

It is collection of different Splunk config files like data inputs, UI and Knowledge Object.

Full Access
Question # 29

How to make Interesting field into a selected field?

A.

Click field in field sidebar -> click YES on the pop-up dialog on upper right side -> check now field should

be visible in the list of selected fields.

B.

Not possible.

C.

Only CLI changes will enable it.

D.

Click Settings -> Find field option -> Drop down select field -> enable selected field -> check now field

should be visible in the list of selected fields.

Full Access
Question # 30

Which of the following are Splunk premium enhanced solutions? (Choose three.)

A.

Splunk User Behavior Analytics (UBA)

B.

Splunk IT Service Intelligence (ITSI)

C.

Splunk Enterprise Security (ES)

D.

Splunk Analytics Security (AS)

Full Access
Question # 31

Which component of Splunk let us write SPL query to find the required data?

A.

Forwarders

B.

Indexer

C.

Heavy Forwarders

D.

Search head

Full Access
Question # 32

When running searches command modifiers in the search string are displayed in what color?

A.

Red

B.

Blue

C.

Orange

D.

Highlighted

Full Access
Question # 33

Which of the following Splunk components typically resides on the machines where data originates?

A.

Indexer

B.

Forwarder

C.

Search head

D.

Deployment server

Full Access
Question # 34

Creating Data Models:

Object ATTRIBUTES do not define ___________.

A.

a base search for the object

B.

fields for the object

Full Access
Question # 35

When a Splunk search generates calculated data that appears in the Statistics tab. in what formats can the results be exported?

A.

CSV, JSON, PDF

B.

CSV, XML JSON

C.

Raw Events, XML, JSON

D.

Raw Events, CSV, XML, JSON

Full Access
Question # 36

How are events displayed after a search is executed?

A.

In chronological order.

B.

Randomly by default.

C.

In reverse chronological order.

D.

Alphabetically according to field name.

Full Access
Question # 37

Which search string is the most efficient?

A.

"failed password"

B.

''failed password"*

C.

index=* "failed password"

D.

index=security "failed password"

Full Access
Question # 38

By default, how long does Splunk retain a search job?

A.

10 Minutes

B.

15 Minutes

C.

1 Day

D.

7 Days

Full Access
Question # 39

Which command automatically returns percent and count columns when executing searches?

A.

top

B.

stats

C.

table

D.

percent

Full Access
Question # 40

How can another user gain access to a saved report?

A.

The owner of the report can edit permissions from the Edit dropdown

B.

Only users with an Admin or Power User role can access other users' reports

C.

Anyone can access any reports marked as public within a shared Splunk deployment

D.

The owner of the report must clone the original report and save it to their user account

Full Access
Question # 41

Parsing of data can happen both in HF and UF.

A.

Yes

B.

No

Full Access
Question # 42

What is Search Assistant in Splunk?

A.

It is only available to Admins.

B.

Such feature does not exist in Splunk.

C.

Shows options to complete the search string

Full Access
Question # 43

The default host name used in Inputs general settings can not be changed.

A.

False

B.

True

Full Access
Question # 44

Which of the following are functions of the stats command?

A.

count, sum, add

B.

count, sum, less

C.

sum, avg, values

D.

sum, values, table

Full Access
Question # 45

In the fields sidebar, which character denotes alphanumeric field values?

A.

#

B.

%

C.

a

D.

a#

Full Access
Question # 46

Which search would return events from the access_combined sourcetype?

A.

Sourcetype=access_combined

B.

Sourcetype=Access_Combined

C.

sourcetype=Access_Combined

D.

SOURCETYPE=access_combined

Full Access
Question # 47

What is the main requirement for creating visualizations using the Splunk UI?

A.

Your search must transform event data into Excel file format first.

B.

Your search must transform event data into XML formatted data first.

C.

Your search must transform event data into statistical data tables first.

D.

Your search must transform event data into JSON formatted data first.

Full Access
Question # 48

When is an alert triggered?

A.

When Splunk encounters a syntax error in a search

B.

When a trigger action meets the predefined conditions

C.

When an event in a search matches up with a data model

D.

When results of a search meet a specifically defined condition

Full Access
Question # 49

Where does Licensing meter happen?

A.

Indexer

B.

Parsing

C.

Heavy Forwarder

D.

Input

Full Access
Question # 50

Every Search in Splunk is also called _____________.

A.

None of the above

B.

Job

C.

Search Only

Full Access
Question # 51

Creating Data Models:

Fields associated with a data set are known as ______.

A.

Attributes

B.

Constraints

Full Access
Question # 52

According to Splunk best practices, which placement of the wildcard results in the most efficient search?

A.

f*il

B.

*fail

C.

fail*

D.

*fail*

Full Access
Question # 53

In the Search and Reporting app, which tab displays timecharts and bar charts?

A.

Events

B.

Patterns

C.

Statistics

D.

Visualization

Full Access
Question # 54

Which of the following is an accurate definition of fields within Splunk?

A.

Inherent entities that exist in event data.

B.

A searchable key/value pair in event data.

C.

Values pulled exclusively from lookup tables.

D.

A non-searchable name/value pair used while indexing data.

Full Access
Question # 55

Which command is used to validate a lookup file?

A.

| lookup products.csv

B.

inputlookup products.csv

C.

I inputlookup products.csv

D.

| lookup definition products.csv

Full Access
Question # 56

Will the queries following below get the same result?

1. index=log sourcetype=error_log status !=100

2. index=log sourcetype=error_log NOT status =100

A.

Yes

B.

No

Full Access
Question # 57

What is a suggested Splunk best practice for naming reports?

A.

Reports are best named using many numbers so they can be more easily sorted.

B.

Use a consistent naming convention so they are easily separated by characteristics such as group and object.

C.

Name reports as uniquely as possible with no overlap to differentiate them from one another.

D.

Any naming convention is fine as long as you keep an external spreadsheet to keep track.

Full Access
Question # 58

Which search will return only events containing the word “error” and display the results as a table that includes

the fields named action, src, and dest?

A.

error | table action, src, dest

B.

error | tabular action, src, dest

C.

error | stats table action, src, dest

D.

error | table column=action column=src column=dest

Full Access
Question # 59

What does the values function of the stats command do?

A.

Lists all values of a given field.

B.

Lists unique values of a given field.

C.

Returns a count of unique values for a given field.

D.

Returns the number of events that match the search.

Full Access
Question # 60

What are Splunk alerts based on?

A.

Dashboards

B.

Searches

C.

Webhooks

D.

Reports

Full Access
Question # 61

In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?

A.

No events will be returned.

B.

Splunk will prompt you to specify an index.

C.

All non-indexed events to which the user has access will be returned.

D.

Events from every index searched by default to which the user has access will be returned.

Full Access
Question # 62

Which search will return the 15 least common field values for the dest_ip field?

A.

sourcetype=firewall | rare num=15 dest_ip

B.

sourcetype=firewall | rare last=15 dest_ip

C.

sourcetype=firewall | rare count=15 dest_ip

D.

sourcetype=firewall | rare limit=15 dest_ip

Full Access
Question # 63

Splunk internal fields contains general information about events and starts from underscore i.e. _ .

A.

True

B.

False

Full Access
Question # 64

Snapping rounds down to the nearest specified unit.

A.

Yes

B.

No

Full Access
Question # 65

What happens when a field is added to the Selected Fields list in the fields sidebar'?

A.

Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field

B.

Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.

C.

Custom selections will replace the Interesting Fields that Splunk populated into the list at search time

D.

The selected field and its corresponding values will appear underneath the events in the search results

Full Access
Question # 66

What are the three main Splunk components?

A.

Search head, GPU, streamer

B.

Search head, indexer, forwarder

C.

Search head, SQL database, forwarder

D.

Search head, SSD, heavy weight agent

Full Access
Question # 67

Which of the following is a false statement about Splunk dashboards?

A.

Dashboards must have a unique dashboard ID within a permission's context.

B.

Splunk dashboards consist of one or more panels displaying data visually in a useful way.

C.

Splunk dashboards may not be directly created from search results without first creating a report.

D.

Splunk dashboard panels can be populated by reports.

Full Access
Question # 68

You can use the following options to specify start and end time for the query range:

A.

earliest=

B.

latest=

C.

beginning=

D.

ending=

E.

All the above

F.

Only 3rd and 4th

Full Access
Question # 69

There are three different search modes in Splunk (Choose three.):

A.

Automatic

B.

Smart

C.

Fast

D.

Verbose

Full Access
Question # 70

!= and NOT are same arguments.

A.

True

B.

False

Full Access
Question # 71

Lookups allow you to overwrite your raw event.

A.

True

B.

False

Full Access
Question # 72

When placed early in a search, which command is most effective at reducing search execution time?

A.

dedup

B.

rename

C.

sort -

D.

fields +

Full Access
Question # 73

Which of the following is a best practice when writing a search string?

A.

Include all formatting commands before any search terms

B.

Include at least one function as this is a search requirement

C.

Include the search terms at the beginning of the search string

D.

Avoid using formatting clauses as they add too much overhead

Full Access