Filters
Question type

Study Flashcards

What user interface component allows for time selection?


A) Time summary
B) Time range picker
C) Search time picker
D) Data source time statistics

E) A) and D)
F) B) and D)

Correct Answer

verifed

verified

Which Boolean operator is always implied between two search terms, unless otherwise specified?


A) OR
B) NOT
C) AND
D) XOR

E) B) and C)
F) C) and D)

Correct Answer

verifed

verified

Uploading local files though Upload options index the file only once.


A) No
B) Yes

C) A) and B)
D) undefined

Correct Answer

verifed

verified

What type of search can be saved as a report?


A) Any search can be saved as a report.
B) Only searches that generate visualizations.
C) Only searches containing a transforming command.
D) Only searches that generate statistics or visualizations.

E) All of the above
F) A) and B)

Correct Answer

verifed

verified

Which of the following index searches would provide the most efficient search performance?


A) index=*
B) index=web OR index=s*
C) (index=web OR index=sales)
D) *index=sales AND index=web*

E) A) and C)
F) None of the above

Correct Answer

verifed

verified

What are the steps to schedule a report?


A) After saving the report, click Schedule.
B) After saving the report, click Event Type.
C) After saving the report, click Scheduling.
D) After saving the report, click Dashboard Panel.

E) C) and D)
F) A) and C)

Correct Answer

verifed

verified

Prefix wildcards might cause performance issues.

A) True
B) False

Correct Answer

verifed

verified

In the fields sidebar, which character denotes alphanumeric field values?


A) #
B) %
C) a
D) a#

E) B) and C)
F) B) and D)

Correct Answer

verifed

verified

What can be configured using the Edit Job Settings menu?


A) Export the result to CSV format.
B) Add the Job results to a dashboard.
C) Schedule the Job to re-run in 10 minutes.
D) Change Job Lifetime from 10 minutes to 7 days.

E) B) and C)
F) A) and B)

Correct Answer

verifed

verified

A field exists in search results, but isn't being displayed in the fields sidebar. How can it be added to the fields sidebar?


A) Click All Fields and select the field to add it to Selected Fields.
B) Click Interesting Fields and select the field to add it to Selected Fields.
C) Click Selected Fields and select the field to add it to Interesting Fields.
D) This scenario isn't possible because all fields returned from a search always appear in the fields sidebar.

E) A) and B)
F) A) and C)

Correct Answer

verifed

verified

We should use heavy forwarder for sending event-based data to Indexers.

A) True
B) False

Correct Answer

verifed

verified

Data summary button just below the search bar gives you the following (Choose three.) :


A) Hosts
B) Sourcetypes
C) Sources
D) Indexes

E) All of the above
F) A) and B)

Correct Answer

verifed

verified

What must be done in order to use a lookup table in Splunk?


A) The lookup must be configured to run automatically.
B) The contents of the lookup file must be copied and pasted into the search bar.
C) The lookup file must be uploaded to Splunk and a lookup definition must be created.
D) The lookup file must be uploaded to the etc/apps/lookups folder for automatic ingestion.

E) A) and D)
F) A) and C)

Correct Answer

verifed

verified

You can use the following options to specify start and end time for the query range:


A) earliest=
B) latest=
C) beginning=
D) ending=
E) All the above
F) Only 3rd and 4th

G) All of the above
H) A) and E)

Correct Answer

verifed

verified

Which search string is the most efficient?


A) "failed password"
B) "failed password"*
C) index=* "failed password"
D) index=security "failed password"

E) A) and B)
F) B) and C)

Correct Answer

verifed

verified

Log filtering/parsing can be done from _____________.


A) Index Forwarders (IF)
B) Universal Forwarders (UF)
C) Super Forwarder (SF)
D) Heavy Forwarders (HF)

E) B) and D)
F) B) and C)

Correct Answer

verifed

verified

Select the correct option that applies to Index time processing (Choose three.) .


A) Indexing
B) Searching
C) Parsing
D) Settings
E) Input

F) D) and E)
G) A) and B)

Correct Answer

verifed

verified

What does the stats command do?


A) Automatically correlates related fields.
B) Converts field values into numerical values.
C) Calculates statistics on data that matches the search criteria.
D) Analyzes numerical fields for their ability to predict another discrete field.

E) All of the above
F) A) and B)

Correct Answer

verifed

verified

What is the correct syntax to count the number of events containing a vendor_action field?


A) count stats vendor_action
B) count stats (vendor_action)
C) stats count (vendor_action)
D) stats vendor_action (count)

E) B) and C)
F) A) and D)

Correct Answer

verifed

verified

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?


A) host
B) index
C) source
D) sourcetype

E) All of the above
F) None of the above

Correct Answer

verifed

verified

Showing 161 - 180 of 187

Related Exams

Show Answer