Pytania i odpowiedzi

Splunk

Zebrane pytania i odpowiedzi do zestawu.
Ilość pytań: 84 Rozwiązywany: 811 razy
Pytanie 21
What syntax is used to link key/value pairs in search strings?
Relational operators such as =, <, or >
Pytanie 22
Which search string returns a filed containing the number of matching events and names that field Event Count?
index=security failure | stats count as “Event Count”
Pytanie 23
Which of the following index searches would provide the most efficient search performance?
(index=web OR index=sales)
Pytanie 24
What is a suggested Splunk best practice for naming reports?
Use a consistent naming convention so they are easily separated by characteristics such as group and object.
Pytanie 25
Which of the following are functions of the stats command?
sum, avg, values
Pytanie 26
At index time, in which field does Splunk store the timestamp value?
_time
Pytanie 27
When looking at a dashboard panel that is based on a report, which of the following is true?
You can modify the search string in the panel, and you can change and configure the visualization.
Pytanie 28
What is a primary function of a scheduled report?
Auto-generated PDF reports of overall data trends.
Pytanie 29
Which command is used to review the contents of a specified static lookup file?
inputlookup
Pytanie 30
Which stats command function provides a count of how many unique values exist for a given field in the result set?
dc(field)
Pytanie 31
A collection of items containing things such as data inputs, UI elements, and knowledge objects is known as what?
An app
Pytanie 32
Which statement is true about Splunk alerts?
Alerts are based on searches that are either run on a scheduled interval or in real-time.
Pytanie 33
What is the purpose of using a by clause with the stats command?
To group the results by one or more fields.
Pytanie 34
In the fields sidebar, which character denotes alphanumeric field values?
a
Pytanie 35
Which of the following searches will return results where fail, 400, and error exist in every event?
error AND (fail AND 400)
Pytanie 36
When placed early in a search, which command is most effective at reducing search execution time?
fields +
Pytanie 37
Which of the following is the most efficient filter for running searches in Splunk?
Time
Pytanie 38
Which of the following is a best practice when writing a search string?
Include the search terms at the beginning of the search string.
Pytanie 39
What type of search can be saved as a report?
Any search can be saved as a report.
Pytanie 40
What can be included in the All Fields option in the sidebar?
Non-interesting fields

Powiązane tematy