Splunk
SPLK-1001
Q1:
Which of the following is a false statement about Splunk dashboards?
○
A
Dashboards must have a unique dashboard ID within a permission's context.○
B
Splunk dashboards consist of one or more panels displaying data visually in a useful way.○
C
Splunk dashboards may not be directly created from search results without first creating a report.○
D
Splunk dashboard panels can be populated by reports.
Splunk
SPLK-1001
Q2:
The four types of Lookups that Splunk provides out-of-the-box are External, KV Store, Geospatial and which of the following?
○
A
Correlated○
B
File-based○
C
Total○
D
Segmented
Splunk
SPLK-1001
Q3:
Which of the following is an accurate definition of fields within Splunk?
○
A
Inherent entities that exist in event data.○
B
A searchable key/value pair in event data.○
C
Values pulled exclusively from lookup tables.○
D
A non-searchable name/value pair used while indexing data.
Splunk
SPLK-1001
Q4:
In the Search and Reporting app, which is a default selected field?
○
A
index○
B
action○
C
_time○
D
host
Splunk
SPLK-1001
Q5:
Which of the following is the best way to create a report that shows the last 24 hours of events?
○
A
Use earliest=-1d@d latest=@d○
B
Set a real-time search over a 24-hour window○
C
Use the time range picket to select ''Yesterday''○
D
Use the time range picker to select ''Last 24 hours''