Pytania i odpowiedzi

Splunk

Zebrane pytania i odpowiedzi do zestawu.
Ilość pytań: 84 Rozwiązywany: 807 razy
Pytanie 1
Which of the following Splunk components typically resides on the machines where data originates?
Forwarder
Pytanie 2
Which of the following searches would return events with failure in index netfw or warn or critical in index netops?
(index=netfw failure) OR (index=netops (warn OR critical))
Pytanie 3
Select the answer that displays the accurate placing of the pipe in the following search string: index=security sourcetype=access_* status=200 stats count by price
index=security sourcetype=access_* status=200 | stats count by price
Pytanie 4
Which of the following represents the Splunk recommended naming convention for dashboards?
Group_Object_Description
Pytanie 5
How can search results be kept longer than 7 days?
By scheduling a report.
Pytanie 6
Which of the following is a Splunk search best practice?
Filter as early as possible.
Pytanie 7
When displaying results of a search, which of the following is true about line charts?
Line charts are optimal for single and multiple series.
Pytanie 8
How are events displayed after a search is executed?
In reverse chronological order.
Pytanie 9
Which of the following is true about user account settings and preferences?
Full name, time zone, and default app can be defined by clicking the login name in the Splunk bar.
Pytanie 10
After running a search, what effect does clicking and dragging across the timeline have?
Filters current search results.
Pytanie 11
What must be done in order to use a lookup table in Splunk?
The lookup file must be uploaded to Splunk and a lookup definition must be created.
Pytanie 12
When sorting on multiple fields with the sort command, what delimiter can be used between the field names in the search?
,
Pytanie 13
Which of the following statements about case sensitivity is true?
Field names ARE case sensitive; field values are NOT.
Pytanie 14
What does the rare command do?
Returns the least common field values of a given field in the results.
Pytanie 15
What does the values function of the stats command do?
Lists unique values of a given field.
Pytanie 16
How do you add or remove fields from search results?
Use fields +to add and fields –to remove.
Pytanie 17
What is the main requirement for creating visualizations using the Splunk UI?
Your search must transform event data into statistical data tables first.
Pytanie 18
What syntax is used to link key/value pairs in search strings?
action=purchase
Pytanie 19
What user interface component allows for time selection?
Time range picker
Pytanie 20
How does Splunk determine which fields to extract from data?
Splunk automatically discovers many fields based on sourcetype and key/value pairs found in the data.

Powiązane tematy