Easter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Splunk Core Certified User Exam Question and Answers

Splunk Core Certified User Exam

Last Update Apr 5, 2024
Total Questions : 244

We are offering FREE SPLK-1001 Splunk exam questions. All you do is to just go and sign up. Give your details, prepare SPLK-1001 free exam questions and then go for complete pool of Splunk Core Certified User Exam test questions that will help you more.

SPLK-1001 pdf

SPLK-1001 PDF

$35  $99.99
SPLK-1001 Engine

SPLK-1001 Testing Engine

$42  $119.99
SPLK-1001 PDF + Engine

SPLK-1001 PDF + Testing Engine

$56  $159.99
Questions 1

It is not possible for a single instance of Splunk to manage the input, parsing and indexing of machine.

Options:

A.  

True

B.  

False

Discussion 0
Questions 2

The better way of writing search query for index is:

Options:

A.  

index=a index=b

B.  

(index=a OR index=b)

C.  

index=(a & b)

D.  

index = a, b

Discussion 0
Questions 3

Which of the following statements about case sensitivity is true?

Options:

A.  

Both field names and field values ARE case sensitive.

B.  

Field names ARE case sensitive; field values are NOT.

C.  

Field values ARE case sensitive; field names ARE NOT.

D.  

Both field names and field values ARE NOT case sensitive.

Discussion 0
Questions 4

According to Splunk best practices, which placement of the wildcard results in the most efficient search?

Options:

A.  

f*il

B.  

*fail

C.  

fail*

D.  

*fail*

Discussion 0
Questions 5

Universal forwarder is recommended for forwarding the logs to indexers.

Options:

A.  

False

B.  

True

Discussion 0
Questions 6

Which of the following is the appropriately formatted SPL search?

Options:

A.  

index=security sourcetype=linux secure (invalid OR failed) | stats count as

"Potential Issues"

B.  

index=security sourcetype=linux secure (invalid OR failed) | stats as

"Potential Issues"

C.  

index—security sourcetype=linux secure (invalid OR failed) | count stats as

"Potential Issues"

D.  

index—security sourcetype=linux secure (invalid OR failed) | count as "Potential Issues"

Discussion 0
Questions 7

These users can create global knowledge objects. (Select all that apply.)

Options:

A.  

users

B.  

power users

C.  

administrators

Discussion 0
Questions 8

When viewing the results of a search, what is an Interesting Field?

Options:

A.  

A field that appears in any event

B.  

A field that appears in every event

C.  

A field that appears in the top 10 events

D.  

A field that appears in at least 20% of the events

Discussion 0
Questions 9

When running searches command modifiers in the search string are displayed in what color?

Options:

A.  

Red

B.  

Blue

C.  

Orange

D.  

Highlighted

Discussion 0
Questions 10

What happens when a field is added to the Selected Fields list in the fields sidebar'?

Options:

A.  

Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field

B.  

Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.

C.  

Custom selections will replace the Interesting Fields that Splunk populated into the list at search time

D.  

The selected field and its corresponding values will appear underneath the events in the search results

Discussion 0
Questions 11

36. Lookups can be private for a user.

Options:

A.  

True

B.  

False

Discussion 0
Questions 12

Which statement describes field discovery at search time?

Options:

A.  

Splunk automatically discovers only numeric fields

B.  

Splunk automatically discovers only alphanumeric fields

C.  

Splunk automatically discovers only manually configured fields

D.  

Splunk automatically discovers only fields directly related to the search results

Discussion 0
Questions 13

Which is the default app for Splunk Enterprise?

Options:

A.  

Splunk Enterprise Security Suite

B.  

Searching and Reporting

C.  

Reporting and Searching

D.  

Splunk apps for Security

Discussion 0
Questions 14

Fields are searchable key value pairs in your event data.

Options:

A.  

True

B.  

False

Discussion 0
Questions 15

Which of the following is a false statement about Splunk dashboards?

Options:

A.  

Dashboards must have a unique dashboard ID within a permission's context.

B.  

Splunk dashboards consist of one or more panels displaying data visually in a useful way.

C.  

Splunk dashboards may not be directly created from search results without first creating a report.

D.  

Splunk dashboard panels can be populated by reports.

Discussion 0
Questions 16

We should use heavy forwarder for sending event-based data to Indexers.

Options:

A.  

False

B.  

True

Discussion 0
Questions 17

Which events will be returned by the following search string?

host=www3 status=503

Options:

A.  

All events that either have a host of www3 or a status of 503.

B.  

All events with a host of www3 that also have a status of 503

C.  

We need more information: we cannot tell without knowing the time range

D.  

We need more information a search cannot be run without specifying an index

Discussion 0
Questions 18

By default search results are not returned in ________ order.

Options:

A.  

Chronological

B.  

Reverser chronological

C.  

ASCIE

D.  

Alphabetical

Discussion 0
Questions 19

Which all time unit abbreviations can you include in Advanced time range picker? (Choose seven.)

Options:

A.  

h

B.  

day

C.  

mon

D.  

yr

E.  

y

F.  

w

G.  

week

Discussion 0
Questions 20

Log filtering/parsing can be done from _____________.

Options:

A.  

Index Forwarders (IF)

B.  

Universal Forwarders (UF)

C.  

Super Forwarder (SF)

D.  

Heavy Forwarders (HF)

Discussion 0
Questions 21

This is what Splunk uses to categorize the data that is being indexed.

Options:

A.  

sourcetype

B.  

index

C.  

source

D.  

host

Discussion 0
Questions 22

When viewing results of a search job from the Activity menu, which of the following is displayed?

Options:

A.  

New events based on the current time range picker

B.  

The same events based on the current time range picker

C.  

The same events from when the original search was executed

D.  

New events in addition to the same events from the original search

Discussion 0
Questions 23

What is the purpose of using a by clause with the stats command?

Options:

A.  

To group the results by one or more fields.

B.  

To compute numerical statistics on each field.

C.  

To specify how the values in a list are delimited.

D.  

To partition the input data based on the split-by fields.

Discussion 0
Questions 24

Will the queries following below get the same result?

1. index=log sourcetype=error_log status !=100

2. index=log sourcetype=error_log NOT status =100

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 25

Select the answer that displays the accurate placing of the pipe in the following search string:

index=security sourcetype=access_* status=200 stats count by price

Options:

A.  

index=security sourcetype=access_* status=200 stats | count by price

B.  

index=security sourcetype=access_* status=200 | stats count by price

C.  

index=security sourcetype=access_* status=200 | stats count | by price

D.  

index=security sourcetype=access_* | status=200 | stats count by price

Discussion 0
Questions 26

When looking at a statistics table, what is one way to drill down to see the underlying events?

Options:

A.  

Creating a pivot table.

B.  

Clicking on the visualizations tab.

C.  

Viewing your report in a dashboard.

D.  

Clicking on any field value in the table.

Discussion 0
Questions 27

Splunk shows data in __________________.

Options:

A.  

ASCII Character order.

B.  

Reverse chronological order.

C.  

Alphanumeric order.

D.  

Chronological order.

Discussion 0
Questions 28

Three basic components of Splunk are (Choose three.):

Options:

A.  

Forwarders

B.  

Deployment Server

C.  

Indexer

D.  

Knowledge Objects

E.  

Index

F.  

Search Head

Discussion 0
Questions 29

When a Splunk search generates calculated data that appears in the Statistics tab. in what formats can the results be exported?

Options:

A.  

CSV, JSON, PDF

B.  

CSV, XML JSON

C.  

Raw Events, XML, JSON

D.  

Raw Events, CSV, XML, JSON

Discussion 0
Questions 30

Which of the following is a correct way to limit search results to display the 5 most common values of a field?

Options:

A.  

| rare top=5

B.  

| top rare=5

C.  

| top limit=5

D.  

| rare limit=5

Discussion 0
Questions 31

Which of the following represents the Splunk recommended naming convention for dashboards?

Options:

A.  

Description_Group_Object

B.  

Group_Description_Object

C.  

Group_Object_Description

D.  

Object_Group_Description

Discussion 0
Questions 32

When sorting on multiple fields with the sort command, what delimiter can be used between the field names in the search?

Options:

A.  

|

B.  

$

C.  

!

D.  

,

Discussion 0
Questions 33

Where does Licensing meter happen?

Options:

A.  

Indexer

B.  

Parsing

C.  

Heavy Forwarder

D.  

Input

Discussion 0
Questions 34

What syntax is used to link key/value pairs in search strings?

Options:

A.  

action+purchase

B.  

action=purchase

C.  

action | purchase

D.  

action equal purchase

Discussion 0
Questions 35

What determines the scope of data that appears in a scheduled report?

Options:

A.  

All data accessible to the User role will appear in the report.

B.  

All data accessible to the owner of the report will appear in the report.

C.  

All data accessible to all users will appear in the report until the next time the report is run.

D.  

The owner of the report can configure permissions so that the report uses either the User role or the owner’s profile at run time.

Discussion 0
Questions 36

Zoom Out and Zoom to Selection re-executes the search.

Options:

A.  

No

B.  

Yes

Discussion 0
Questions 37

Which of the following are not true about lookups? (Select all that apply.)

Options:

A.  

Lookups can be time based

B.  

Search results can be used to populate a lookup table

C.  

Splunk DB Connect can be used to populate a lookup table from relational databases

D.  

Output from a script can be used to populate a lookup table

E.  

Lookup have a 10mg maximum size limit

Discussion 0
Questions 38

Which of the following searches will show the number of categoryld used by each host?

Options:

A.  

Sourcetype=access_* |sum bytes by host

B.  

Sourcetype=access_* |stats sum(categorylD) by host

C.  

Sourcetype=access_* |sum(bytes) by host

D.  

Sourcetype=access_* |stats sum by host

Discussion 0
Questions 39

Which of the following is a metadata field assigned to every event in Splunk?

Options:

A.  

host

B.  

owner

C.  

bytes

D.  

action

Discussion 0
Questions 40

Which of the following is a Splunk internal field?

Options:

A.  

_raw

B.  

host

C.  

_host

D.  

index

Discussion 0
Questions 41

Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip

Options:

A.  

10

B.  

50

C.  

100

D.  

20

Discussion 0
Questions 42

What does the rare command do?

Options:

A.  

Returns the least common field values of a given field in the results.

B.  

Returns the most common field values of a given field in the results.

C.  

Returns the top 10 field values of a given field in the results.

D.  

Returns the lowest 10 field values of a given field in the results.

Discussion 0
Questions 43

What is a primary function of a scheduled report?

Options:

A.  

Auto-detect changes in performance

B.  

Auto-generated PDF reports of overall data trends

C.  

Regularly scheduled archiving to keep disk space use low

D.  

Triggering an alert in your Splunk instance when certain conditions are met

Discussion 0
Questions 44

Field names are case sensitive and field value are not.

Options:

A.  

True

B.  

False

Discussion 0
Questions 45

You can view the search result in following format (Choose three.):

Options:

A.  

Table

B.  

Raw

C.  

Pie Chart

D.  

List

Discussion 0
Questions 46

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

Options:

A.  

host

B.  

index

C.  

source

D.  

sourcetype

Discussion 0
Questions 47

What is Search Assistant in Splunk?

Options:

A.  

It is only available to Admins.

B.  

Such feature does not exist in Splunk.

C.  

Shows options to complete the search string

Discussion 0
Questions 48

Keywords are highlighted when you mouse over search results and you can click this search result to (Choose three.):

Options:

A.  

Open new search.

B.  

Exclude the item from search.

C.  

None of the above.

D.  

Add the item to search

Discussion 0
Questions 49

How can results from a specified static lookup file be displayed?

Options:

A.  

lookup command

B.  

inputlookup command

C.  

Settings > Lookups > Input

D.  

Settings > Lookups > Upload

Discussion 0
Questions 50

Splunk Enterprise is used as a Scalable service in Splunk Cloud.

Options:

A.  

True

B.  

False

Discussion 0
Questions 51

This search will return 20 results. SEARCH: error | top host limit = 20

Options:

A.  

True

B.  

False

Discussion 0
Questions 52

Which component of Splunk let us write SPL query to find the required data?

Options:

A.  

Forwarders

B.  

Indexer

C.  

Heavy Forwarders

D.  

Search head

Discussion 0
Questions 53

Which command is used to validate a lookup file?

Options:

A.  

| lookup products.csv

B.  

inputlookup products.csv

C.  

I inputlookup products.csv

D.  

| lookup definition products.csv

Discussion 0
Questions 54

Lookups allow you to overwrite your raw event.

Options:

A.  

True

B.  

False

Discussion 0
Questions 55

By default, how long does Splunk retain a search job?

Options:

A.  

10 Minutes

B.  

15 Minutes

C.  

1 Day

D.  

7 Days

Discussion 0
Questions 56

Which symbol is used to snap the time?

Options:

A.  

@

B.  

&

C.  

*

D.  

#

Discussion 0
Questions 57

Which of the following is an accurate definition of fields within Splunk?

Options:

A.  

Inherent entities that exist in event data.

B.  

A searchable key/value pair in event data.

C.  

Values pulled exclusively from lookup tables.

D.  

A non-searchable name/value pair used while indexing data.

Discussion 0
Questions 58

When a search returns __________, you can view the results as a list.

Options:

A.  

a list of events

B.  

transactions

C.  

statistical values

Discussion 0
Questions 59

Beginning parentheses is automatically highlighted to guide you on the presence of complimenting

parentheses.

Options:

A.  

No

B.  

Yes

Discussion 0
Questions 60

You can on-board data to Splunk using following means (Choose four.):

Options:

A.  

Props

B.  

CLI

C.  

Splunk Web

D.  

savedsearches.conf

E.  

Splunk apps and add-ons

F.  

indexes.conf

G.  

inputs.conf

Discussion 0
Questions 61

What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?

Options:

A.  

the_questionnaire _pedia

B.  

the_questionnaire pedia

C.  

the_questionnaire_pedia

D.  

the_questionnaire Pedia

Discussion 0
Questions 62

Which of the following is the recommended way to create multiple dashboards displaying data from the same search?

Options:

A.  

Save the search as a report and use it in multiple dashboards as needed

B.  

Save the search as a dashboard panel for each dashboard that needs the data

C.  

Save the search as a scheduled alert and use it in multiple dashboards as needed

D.  

Export the results of the search to an XML file and use the file as the basis of the dashboards

Discussion 0
Questions 63

Use this command to use lookup fields in a search and see the lookup fields in the field sidebar.

Options:

A.  

inputlookup

B.  

lookup

Discussion 0
Questions 64

When refining search results, what is the difference in the time picker between real-time and relative time ranges?

Options:

A.  

Real-time searches happen instantly, while relative searches happen at a scheduled time.

B.  

Real-time searches display results from a rolling time window, while relative searches display results from a set length of time.

C.  

Real-time searches run constantly in the background, while relative searches only run when certain criteria are met.

D.  

Real-time represents events that have happened in a set time window, while relative will display results from a rolling time window.

Discussion 0
Questions 65

Select the correct option that applies to Index time processing (Choose three.).

Options:

A.  

Indexing

B.  

Searching

C.  

Parsing

D.  

Settings

E.  

Input

Discussion 0
Questions 66

In the Search and Reporting app, which is a default selected field?

Options:

A.  

index

B.  

action

C.  

_time

D.  

host

Discussion 0
Questions 67

The four types of Lookups that Splunk provides out-of-the-box are External, KV Store, Geospatial and which of the following?

Options:

A.  

Correlated

B.  

File-based

C.  

Total

D.  

Segmented

Discussion 0
Questions 68

By default, which of the following is a Selected Field?

Options:

A.  

action

B.  

clientip

C.  

categoryld

D.  

sourcetype

Discussion 0
Questions 69

Assuming a user has the capability to edit reports, which of the following are editable?

Options:

A.  

Acceleration, schedule, permissions

B.  

The report’s name, schedule, permissions

C.  

The report’s name, acceleration, schedule

D.  

The report’s name, acceleration, permissions

Discussion 0
Questions 70

In the fields sidebar, which character denotes alphanumeric field values?

Options:

A.  

#

B.  

%

C.  

a

D.  

a#

Discussion 0
Questions 71

In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?

Options:

A.  

No events will be returned.

B.  

Splunk will prompt you to specify an index.

C.  

All non-indexed events to which the user has access will be returned.

D.  

Events from every index searched by default to which the user has access will be returned.

Discussion 0
Questions 72

This clause is used to group the output of a stats command by a specific name.

Options:

A.  

Rex

B.  

As

C.  

List

D.  

By

Discussion 0
Questions 73

What does the following specified time range do?

earliest=-72h@h latest=@d

Options:

A.  

Look back 3 days ago and prior

B.  

Look back 72 hours up to one day ago

C.  

Look back 72 hours, up to the end of today

D.  

Look back from 3 days ago up to the beginning of today

Discussion 0