Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

Splunk Fundamentals 1

Rating
-
Sold
-
Pages
26
Grade
A+
Uploaded on
15-08-2024
Written in
2024/2025

Machine data is only generated by web servers. - answer-False Search requests are processed by the ___________. - answer-Indexers Search strings are sent from the _________. - answer-Search Head In most Splunk deployments, ________ serve as the primary way data is supplied for indexing. - answer-Forwarders Which of these is *not* a main component of Splunk? A) Search and investigate. B) Compress and archive. C) Add knowledge. D) Collect and index data. - answer-B) Compress and archive What are the three main processing components of Splunk? *(Select all that apply.)* A) Indexers B) Deployment Maker C) Search Heads D) Forwarders E) Distributors - answer-A) Indexers C) Search Heads D) Forwarders _________ define what users can do in Splunk. A) Tokens B) Disk permissions C) Roles - answer-C) Roles This role will only see their own knowledge objects and those that have been shared with them. A) User B) Power C) Admin - answer-A) User T/F: You can launch and manage apps from the home app. - answer-True What are the three main default roles in Splunk Enterprise? *(Select all that apply.)* A) King B) User C) Manager D) Admin E) Power - answer-B) User D) Admin E) Power Which apps ship with Splunk Enterprise? *(Select all that apply.)* A) Home App B) Sideview Utils C) Search & Reporting D) DB Connect - answer-A) Home App C) Search & Reporting The default username and password for a newly installed Splunk instance is: A) username and password B) admin and changeme C) admin and 12345 D) buttercup and rawks - answer-B) admin and changeme Files indexed using the *upload* input option get indexed _____. A) Each time Splunk restarts. B) Every hour. C) On every search. D) Once. - answer-D) Once. T/F: The monitor input option will allow you to continuously monitor files. - answer-True Splunk knows where to break the event, where the time stamp is located and how to automatically create field value pairs using these. A) Line breaks B) Source types C) File names - answer-B) Source types Splunk uses ______________ to categorize the type of data being indexed. - answer-sourcetype In most production environments, _____________ will be used as your the source of data input. - answer-Forwarders How is the *asterisk* used in Splunk search? A) As a wildcard. B) To make a nose for your clown emoticon. C) As a place holder. D) To add up numbers. - answer-A) As a wildcard. Which following search mode toggles behavior based on the type of search being run? A) Smart B) Fast C) Verbose - answer-A) Smart T/F: When zooming in on the event time line, a new search is run. - answer-False T/F: These searches will return the same results... failed password failed AND password - answer-True A search job will remain active for _____ minutes after it is run. A) 5 B) 10 C) 30 D) 60 E) 90 - answer-B) 10 What attributes describe the field below? a dest 4 (Select all that apply.) A) It contains 4 values. B) It contains numerical values. C) It cannot be used in a search. D) It contains string values. - answer-A) It contains 4 values. D) It contains string values. T/F: Wildcards cannot be used with field searches. - answer-False T/F: Field values are case sensitive. - answer-False Which is not a comparison operator in Splunk? (Select your answer.) A) B) ?= C) = D) != E) = - answer-?= Field names are ________. *(Select all that apply.)* A) Always capitalized. B) Not important in Splunk. C) Case sensitive. D) Case insensitive. - answer-C) Case sensitive This symbol is used in the "Advanced" section of the time range picker to round down to nearest unit of specified time. (Select your answer.) A) % B) ^ C) @ D) & E) * - answer-C) @ T/F: Time to search can only be set by the time range picker. - answer-False What is the most efficient way to filter events in Splunk? A) By time. B) Using booleans. C) With an asterisk. - answer-A) By time. T/F: As a general practice, exclusion is better than inclusion in a Splunk search. - answer-False Having separate indexes allows: *(Select all that apply.)* A) Faster Searches.

Show more Read less
Institution
Splunk Fundamentals 1
Course
Splunk Fundamentals 1

Content preview

SPLUNK FUNDAMENTALS 1
EXAMINATION 2024
Machine data is only generated by web servers. - answer-False

Search requests are processed by the ___________. - answer-Indexers

Search strings are sent from the _________. - answer-Search Head

In most Splunk deployments, ________ serve as the primary way data is supplied for indexing. -
answer-Forwarders

Which of these is *not* a main component of Splunk?

A) Search and investigate.
B) Compress and archive.
C) Add knowledge.
D) Collect and index data. - answer-B) Compress and archive

What are the three main processing components of Splunk?

*(Select all that apply.)*

A) Indexers
B) Deployment Maker
C) Search Heads
D) Forwarders
E) Distributors - answer-A) Indexers
C) Search Heads
D) Forwarders

_________ define what users can do in Splunk.

A) Tokens
B) Disk permissions
C) Roles - answer-C) Roles

This role will only see their own knowledge objects and those that have been shared with them.

A) User
B) Power

,C) Admin - answer-A) User

T/F:
You can launch and manage apps from the home app. - answer-True

What are the three main default roles in Splunk Enterprise?

*(Select all that apply.)*

A) King
B) User
C) Manager
D) Admin
E) Power - answer-B) User
D) Admin
E) Power

Which apps ship with Splunk Enterprise?

*(Select all that apply.)*

A) Home App
B) Sideview Utils
C) Search & Reporting
D) DB Connect - answer-A) Home App
C) Search & Reporting

The default username and password for a newly installed Splunk instance is:

A) username and password
B) admin and changeme
C) admin and 12345
D) buttercup and rawks - answer-B) admin and changeme

Files indexed using the *upload* input option get indexed _____.

A) Each time Splunk restarts.
B) Every hour.
C) On every search.
D) Once. - answer-D) Once.

T/F:
The monitor input option will allow you to continuously monitor files. - answer-True

, Splunk knows where to break the event, where the time stamp is located and how to
automatically create field value pairs using these.

A) Line breaks
B) Source types
C) File names - answer-B) Source types

Splunk uses ______________ to categorize the type of data being indexed. - answer-sourcetype

In most production environments, _____________ will be used as your the source of data
input. - answer-Forwarders

How is the *asterisk* used in Splunk search?

A) As a wildcard.
B) To make a nose for your clown emoticon.
C) As a place holder.
D) To add up numbers. - answer-A) As a wildcard.

Which following search mode toggles behavior based on the type of search being run?

A) Smart
B) Fast
C) Verbose - answer-A) Smart

T/F:
When zooming in on the event time line, a new search is run. - answer-False

T/F:
These searches will return the same results...

failed password

failed AND password - answer-True

A search job will remain active for _____ minutes after it is run.

A) 5
B) 10
C) 30
D) 60
E) 90 - answer-B) 10

What attributes describe the field below?

Written for

Institution
Splunk Fundamentals 1
Course
Splunk Fundamentals 1

Document information

Uploaded on
August 15, 2024
Number of pages
26
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$12.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TOPDOCTOR Abacus College, Oxford
Follow You need to be logged in order to follow users or courses
Sold
10
Member since
2 year
Number of followers
5
Documents
3395
Last sold
8 months ago
TOPGRADER!!

Looking for relevant and updated study material to help you ace your exams? TOPTIERGRADES has your back!!! I have essential exams, test-banks, study bites, assignments all graded A+, Have Complete solutions, and are updated regularly. Please feel free to message me if you are looking for a specific test bank that is not listed on my profile or want a test bank or exam sent to you directly as google doc link. In the event that any of the materials have an issue, please let me know and I\'ll do my best to resolve it or provide an alternative. Thank You & All The Very BEST!!!!!

Read more Read less
5.0

1 reviews

5
1
4
0
3
0
2
0
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions