Fund1 Flashcards
Machine data is always structured.
False
Which of these is not a main component of Splunk?
- Compress and archive
- Search and investigate
- Add knowledge
- Collect and index data
Compress and archive
Machine data makes up for more than ___% of the data accumulated by organizations.
90
Machine data is only generated by web servers.
False
Search strings are sent from the _________.
Search Head
When a search is sent to splunk, it becomes a _____.
Search Job
Commands that create statistics and visualizations are called _______________ commands.
Transforming
Which search mode toggles behavior based on the type of search being run?
Smart
Which is not a comparison operator in Splunk? = > <= != ?=
?=
Events are always returned in chronological order.
False
As a general practice, exclusion is better than inclusion in a Splunk search.
False
This symbol is used in the “Advanced” section of the time range picker to round down to nearest unit of specified time.
@
What is the most efficient way to filter events in Splunk?
By Time
Which command removes results with duplicate field values?
Dedup
What is missing from this search?
{ sourcetype=a* | rename ip as “User IP” | table User IP }
Quotation marks around User IP.