Professional Documents
Culture Documents
Test - Splunk Core Certified User - Quizlet
Test - Splunk Core Certified User - Quizlet
NOM
1. What are the three main methods for creating tables and visualizations in Splunk?
65 %
INCORRECT
search , pivot ,
LA RÉPONSE
1) Running a Report.
2) Using the Pivot interface.
3) Using the transforming commands in the search bar.
2. What search command changes the name of a field to a different specified name?
CORRECT
Rename
INCORRECT
Fowarders
LA RÉPONSE
Forwarders
A) Home App
B) Sideview Utils
C) Search & Reporting
D) DB Connect
INCORRECT
C
LA RÉPONSE
A) Home App
C) Search & Reporting
INCORRECT
https://quizlet.com/349146707/test 1/5
15/01/2020 Test : Splunk Core Certified User | Quizlet
1. 1) Presets (default) A. What are the three ways can you share a particular search
2) Relative you've created?
3) Real-time
4) Date Range B. Which of the following is a valid CIDR aware Splunk search:
5) Date & Time Range
6) Advanced A) clientip="141.146.8.0/24"
B) clientip="141.146.8.*"
CORRECT
C) Both A & B
E. What are the six time range tabs in the time picker drop
D) None of the above
down menu?
A) Indexers
A) clientip="141.146.8.0/24"
B) Deployment Maker
B) clientip="141.146.8.*"
C) Search Heads
C) Both A & B
D) Forwarders
D) None of the above
E) Distributors
3. A) Indexers
D. What does the following search do?
C) Search Heads
D) Forwarders
index=web sourcetype=access_* status=503 | stats
CORRECT
sum(price) as lost_revenue | eval lost_revenue = "$" +
C. What are the three main processing components of tostring(lost_revenue, "commas")
Splunk?
E. What are the six time range tabs in the time picker drop
(Select all that apply.) down menu?
A) Indexers
B) Deployment Maker
C) Search Heads
D) Forwarders
E) Distributors
4. In the bottom right of the search bar there are job options,
which allow you to do the following:
CORRECT
https://quizlet.com/349146707/test 2/5
15/01/2020 Test : Splunk Core Certified User | Quizlet
CORRECT
1. Machine data makes up for more than ___% of the data accumulated by organizations.
"access denied"
B. Inclusion is generally better than exclusion. Searching for "access denied" is faster than NOT "access granted"
C. 90
D. Splunk DB Connect
A. 1) Pivot
2) Search
1) Search terms
2) Commands
3) Functions
4) Arguments
C. 5) Clauses
3. T/F:
Matching search terms are highlighted.
A. False
B. B) 10
C. B) AND
D. True
https://quizlet.com/349146707/test 3/5
15/01/2020 Test : Splunk Core Certified User | Quizlet
age
5. Searching exact phrases, such as best effort or unit 0837 require the use of what?
1) timestamp
2) host
3) source
A. 4) sourcetype
sort -FieldName
OR
sort +FieldName
i.e. ...
5 questions vrai/faux
1. T/F:
Machine data is only generated by web servers. → False
INCORRECT
Faux
LA RÉPONSE
Vrai
2. How would you access recent or saved search jobs? → When the items searched against have punctuation, such as SF-
RT_5G01
But due to the way Splunk indexes punctuation (such as underscore or dash), this search would likely fail.
INCORRECT
Vrai
LA RÉPONSE
Faux
Réponse correcte : → Click the Activity drop down menu in the top right of the search app and then select the Jobs
option.
https://quizlet.com/349146707/test 4/5
15/01/2020 Test : Splunk Core Certified User | Quizlet
3. What are the three required parts of a pivot? → The pivot command is a generating command and must be first in a search
pipeline. It requires a large number of inputs: the data model, the data model object, and pivot elements.
CORRECT
Vrai
INCORRECT
Vrai
LA RÉPONSE
Faux
Réponse correcte : → 1) Compact
2) Full
5. When creating a search, certain keywords will be colored by syntax. What does the following color map to?...
CORRECT
Faux
Réponse correcte : → Green = Command Arguments
https://quizlet.com/349146707/test 5/5