me Flashcards

1
Q

Which search string only returns events from hostWWW3

A

host=WWW3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

By default, how long does Splunk retain a search job?

A

10 Minutes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What must be done before an automatic lookup can be created?

A

The lookup definition must be created.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which of the following Splunk components typically resides on the machines where data originates?

A

Forwarder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What determines the scope of data that appears in a scheduled report?

A

The owner of the report can configure permissions so that the report uses either the User role or the owner’s profile at run time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When writing searches in Splunk, which of the following is true about Booleans?

A

They must be uppercase.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which of the following searches would return events with failure in index netfw or warn or critical in index netops

A

(index=netfw failure) OR (index=netops (warn OR critical))

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Select the answer that displays the accurate placing of the pipe in the following search string:
index=security sourcetype=access_* status=200 stats count by price

A

index=security sourcetype=access_* status=200 | stats count by price

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which of the following constraints can be used with the top command?

A

limit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When editing a dashboard, which of the following are possible options?

A

Modify the chart type displayed in a dashboard panel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

When running searches, command modifiers in the search string are displayed in what color?

A

Orange

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which of the following represents the Splunk recommended naming convention for dashboards?

A

Group_Object_Description

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How can search results be kept longer than 7 days?

A

By changing the job settings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which of the following is a Splunk search best practice?

A

Filter as early as possible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

When looking at a dashboard panel that is based on a report, which of the following is true?

A

You cannot modify the search string in the panel, but you can change and configure the visualization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which of the following are common constraints of the top command?

A

limit, count

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

When displaying results of a search, which of the following is true about line charts?

A

Line charts are optimal for multiple series with 3 or more columns

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How are events displayed after a search is executed?

A

in reverse chronological order

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which of the following is true about user account settings and preferences?

A

Full name, time zone, and default app can be defined by clicking the login name in the Splunk bar.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is a primary function of a scheduled report?

A

Triggering an alert in your Splunk instance when certain conditions are met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

After running a search, what effect does clicking and dragging across the timeline have?

A

Moves to past or future events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which command is used to review the contents of a specified static lookup file?

A

inputlookup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What must be done in order to use a lookup table in Splunk?

A

The lookup file must be uploaded to Splunk and a lookup definition must be created.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

When sorting on multiple fields with the sort command, what delimiter can be used between the field names in the search?

A

,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Which time range picker configuration would return real-time events for the past 30 seconds?

A

Real-time - Earliest: 30-seconds ago, Latest: Now

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What is the correct syntax to count the number of events containing a vendor_action field?

A

stats count (vendor_action)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is one benefit of creating dashboard panels from reports

A

It makes the dashboard more efficient because it only has to run one search string.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

A

host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which of the following statements about case sensitivity is true?

A

Field names ARE case sensitive; field values are NOT.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What does the rare command do?

A

Returns the least common field values of a given field in the results.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

When an alert action is configured to run a script, Splunk must be able to locate the script.
Which is one of the directories Splunk will look in to find the script?

A

$SPLUNK_HOME/bin/scripts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Which Boolean operator is always implied between two search terms, unless otherwise specified?

A

AND

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What does the values function of the stats command do?

A

Returns a count of unique values for a given field.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Which stats command function provides a count of how many unique values exist for a given field in the result set?

A

dc(field)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

A collection of items containing things such as data inputs, UI elements, and knowledge objects is known as what?

A

An app

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Which statement is true about Splunk alerts?

A

Alerts are based on searches that are either run on a scheduled interval or in real-time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What is the purpose of using a by clause with the stats command?

A

To group the results by one or more fields.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

How do you add or remove fields from search results?

A

Use fields +to add and fields –to remove

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

A field exists in search results, but isn’t being displayed in the fields sidebar.
How can it be added to the fields sidebar?

A

Click All Fields and select the field to add it to Selected Fields.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

In the fields sidebar, which character denotes alphanumeric field values?

A

a

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

What is the main requirement for creating visualizations using the Splunk UI?

A

Your search must transform event data into XML formatted data first.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

What syntax is used to link key/value pairs in search strings?

A

action=purchase

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

What user interface component allows for time selection?

A

Time range picker

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

Which of the following searches will return results where fail, 400, and error exist in every event?

A

error AND (fail OR 400)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

When placed early in a search, which command is most effective at reducing search execution time?dedup

A

dedup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Which of the following is the most efficient filter for running searches in Splunk?

A

sourcetype

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

How does Splunk determine which fields to extract from data?

A

Splunk automatically discovers many fields based on sourcetype and key/value pairs found in the data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

Which of the following file types is an option for exporting Splunk search results?

A

PDF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

What syntax is used to link key/value pairs in search strings?

A

Relational operators such as =,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

Which search string returns a filed containing the number of matching events and names that field Event Count?

A

index=security failure | stats count by “Event Count”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

Which search would return events from the access_combined sourcetype?

A

Sourcetype=access_combined

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

Which of the following index searches would provide the most efficient search performance?

A

index=web OR index=s*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

What is a suggested Splunk best practice for naming reports?

A

Use a consistent naming convention so they are easily separated by characteristics such as group and object.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?

A

Events from every index searched by default to which the user has access will be returned.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

When looking at a statistics table, what is one way to drill down to see the underlying events?

A

Clicking on any field value in the table

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

In the Splunk interface, the list of alerts can be filtered based on which characteristics?

A

App, Time Window, Type, and Severity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

What are the steps to schedule a report?

A

After saving the report, click Schedule.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

In the fields sidebar, what indicates that a field is numeric?

A

A # symbol to the left of the field name.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

Which of the following are functions of the stats command?

A

sum, avg, values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

At index time, in which field does Splunk store the timestamp value?

A

_time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

Which of the following is a best practice when writing a search string?

A

Avoid using formatting clauses, as they add too much overhead.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

What type of search can be saved as a report?

A

Any search can be saved as a report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q

What can be included in the All Fields option in the sidebar?

A

field descriptions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q

When viewing the results of a search, what is an Interesting Field?

A

A field that appears in at least 20% of the events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

When a Splunk search generates calculated data that appears in the Statistics tab, in what formats can the results be exported?

A

CSV, XML, JSON

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

Which search matches the events containing the terms “error” and “fail”

A

index=security error OR fail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

Which of the following is an option after clicking an item in search results?

A

adding the item to the search

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
68
Q

Which of the following fields is stored with the events in the index?

A

source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
69
Q

Which of the following is the recommended way to create multiple dashboards displaying data from the same search?

A

Export the results of the search to an XML file and use the file as the basis of the dashboards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
70
Q

What does the following specified time range do?

earliest=-72h@h latest=@d

A

Look back 72 hours, up to the end of today.

71
Q

Which events will be returned by the following search string?

host=www3 status=50

A

All events with a host of www3 that also have a status of 503

72
Q

What does the stats command do?

A

Calculates statistics on data that matches the search criteria.

73
Q

Which is primary function of the timeline located under the search bar?

A

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

74
Q

What can be configured using the Edit Job Settings menu?

A

Change Job Lifetime from 10 minutes to 7 days.

75
Q

Which command is used to validate a lookup file?

A

inputlookup products.cs

76
Q

Which statement is true about the top command?

A

It returns the top 10 results.
It displays the output in table format.
It returns the count and percent columns per row.

77
Q

How can another user gain access to a saved report?

A

The owner of the report can edit permissions from the Edit dropdown.

78
Q

What is the primary use for the rare command

A

To find the least common values of a field in a dataset.

79
Q

What happens when a field is added to the Selected Fields list in the fields sidebar?

A

The selected field and its corresponding values will appear underneath the events in the search results.

80
Q

By default, which of the following is a Selected Field?

A

sourcetype

81
Q

According to Splunk best practices, which placement of the wildcard results in the most efficient search?

A

fail*

82
Q

Which command automatically returns percent and count columns when executing searches?

A

top

83
Q

Which command automatically returns percent and count columns when executing searches?

A

top

84
Q

Which search string is the most efficient?

A

index=security “failed password”

85
Q

Which search string matches only events with the status_code of 404?

A

status_code>403 status_code<405

86
Q

_______________ transforms raw data into events and distributes the results into an index.

A

Indexer

87
Q

Documentations for Splunk can be found at docs.splunk.com

A

True

88
Q

Which component of Splunk is primarily responsible for saving data?

A

Indexer

89
Q

Universal forwarder is recommended for forwarding the logs to indexers.

A

True

90
Q

Splunk apps are used for following

A

Designed to cater numerous use cases and empower Splunk.
Allows multiple workspaces for different use cases/user roles.
It is collection of different Splunk config files like data inputs, UI and Knowledge Object.

91
Q

Three basic components of Splunk are

A

Indexer
Forwarder
Search Head

92
Q

What is Splunk?

A

Splunk is a software platform to search, analyze and visualize the machine-generated data.

93
Q

We should use heavy forwarder for sending event-based data to Indexers.

A

False

94
Q

Splunk Enterprise is used as a Scalable service in Splunk Cloud.

A

True

95
Q

Which component of Splunk let us write SPL query to find the required data?

A

Search Head

96
Q

All components are installed and administered in Splunk Enterprise on-premise.

A

True

97
Q

Log filtering/parsing can be done from _____________.

A

Heavy Forwarders (HF)

98
Q

Which is the default app for Splunk Enterprise?

A

Searching and Reporting

99
Q

What kind of logs can Splunk Index?

A

All firewall, web server, database, router and switch logs

100
Q

Portal for Splunk apps can be accessed through www.splunkbase.com

A

True

101
Q

Splunk shows data in __________________

A

Reverse chronological order.

102
Q

Which of the following can be used as wildcard search in Splunk?

A

*

103
Q

What result will you get with following search index=test sourcetype=”The_Questionnaire_P*”

A

the_questionnaire_pedia

104
Q

Prefix wildcards might cause performance issues.

A

True

105
Q

Machine data can be in structured and unstructured format.

A

True

106
Q

Field names are case sensitive.

A

True

107
Q

Splunk internal fields contains general information about events and starts from underscore i.e. _ .

A

True

108
Q

How many main user roles do you have in Splunk?

A

3

109
Q

Which of the following are Splunk premium enhanced solutions?

A

Splunk User Behavior Analytics (UBA)
Splunk IT Service Intelligence (ITSI)
Splunk Enterprise Security (ES)

110
Q

Fields are searchable name and value pairings that differentiates one event from another.

A

True

111
Q

Splunk extracts fields from event data at index time and at search time.

A

True

112
Q

Field values are case sensitive

A

False

113
Q

Splunk indexes the data on the basis of timestamps.

A

True

114
Q

______________ is the default web port used by Splunk.

A

8000

115
Q

Which of the following statements are correct about Search & Reporting App?

A

Can be accessed by Apps > Search & Reporting.
Provides default interface for searching and analyzing logs.
Enables the user to create knowledge object, reports, alerts and dashboards

116
Q

Parsing of data can happen both in HF and Indexer.

A

Yes

117
Q

Monitor option in Add Data provides _______________.

A

Both One-time and continuous monitoring.

118
Q

License Meter runs before data compression.

A

Yes

119
Q

Forward Option gather and forward data to indexers over a receiving port from remote machines.

A

True

120
Q

You can on-board data to Splunk using following means

A

CLI
Splunk Web
Splunk apps and add-ons
inouts.conf

121
Q

Data sources being opened and read applies to

A

input phase

122
Q

Select the correct option that applies to Index time processing

A

Indexing
Parsing
Input

123
Q

Splunk automatically determines the source type for major data types.

A

True

124
Q

Parsing of data can happen both in HF and UF.

A

No

125
Q

Upload option creates inputs.conf

A

No

126
Q

Splunk index time process can be broken down into __________ phase

A

3

127
Q

In monitor option you can select the following options in GUI.

A

Filed & Directories, HTTP Event Collector (HEC), TCP/UDP and Scripts

128
Q

Uploading local files though Upload options index the file only once

A

Yes

129
Q

Which of the statements are correct about HF?

A

Parsing
Masking
Forwarding

130
Q

Where does Licensing meter happen?

A

Indexer

131
Q

Matching search terms are highlighted.

A

Yes

132
Q

Beginning parentheses is automatically highlighted to guide you on the presence of complimenting parentheses.

A

Yes

133
Q

Zoom Out and Zoom to Selection re-executes the search.

A

Yes

134
Q

Every Search in Splunk is also called _____________.

A

Job

135
Q

Matching of parentheses is a feature of Splunk Assistant.

A

Yes

136
Q

Search Assistant is enabled by default in the SPL editor with compact settings.

A

Yes

137
Q

What is Search Assistant in Splunk?

A

Shows options to complete the search string.

138
Q

@ Symbol can be used in advanced time unit option.

A

Yes

139
Q

The new data uploaded in Splunk are shown in ________________.

A

Real-time

140
Q

You can use the following options to specify start and end time for the query range

A

beginning=

ending=

141
Q

You can change the App context in Input setting.

A

Yes

142
Q

The default host name used in Inputs general settings can not be changed.

A

False

143
Q

Events in Splunk are automatically segregated using data and time.

A

Yes

144
Q

You are able to create new Index in Data Input settings.

A

Yes

145
Q

Splunk Parses data into individual events, extracts time, and assigns metadata.

A

True

146
Q

Which of the statements is correct regarding click and drag option in timeline?

A

The new result after selecting the range by dragging filters the events and displays the most recent first.

147
Q

Which symbol is used to snap the time?

A

@

148
Q

Which of the statements are correct

A

Zoom to selection: Narrows the time range and re-executes the search.
Format Timeline: Hides or shows the timeline in different views.
Zoom-out: Expands the time focus and re-executes the search.

149
Q

There are three different search modes in Splunk

A

Smart, Fast, Verbose

150
Q

Select the statements that are true for timeline in Splun

A

Timeline shows distribution of events specified in the time range in the form of bar.
Single click to see the result for particular time period.
You can click and drag across the bar for selecting the range.
You can hover your mouse for details like total events, time and date.

151
Q

Keywords are highlighted when you mouse over search results and you can click this search result to

A

Open new search.
Exclude the item from search.
Add the item to search.

152
Q

You can view the search result in following format

A

Table
Raw
List

153
Q

Snapping rounds down to the nearest specified unit.

A

Yes

154
Q

Data summary button just below the search bar gives you the following

A

Hosts
Sourcetypes
Sources

155
Q

What options do you get after selecting timeline?

A

Zoom to selection
Format Timeline
Deselect
Zoom Out

156
Q

At the time of searching the start time is 03:35:08.

Will it look back to 03:00:00 if we use -30m@h in searching?

A

Yes

157
Q

Can you stop or pause the searching?

A

Yes

158
Q

You can also specify a time range in the search bar. You can use the following for beginning and ending for a time range

A

earliest=

latest=

159
Q

Which all time unit abbreviations can you include in Advanced time range picker?

A
h
mon
y
w
d
s
m
160
Q

Interesting fields are the fields that have at least 20% of resulting fields.

A

True

161
Q

How to make Interesting field into a selected field

A

Click field in field sidebar -> click YES on the pop-up dialog on upper right side -> check now field should be visible in the list of selected fields

162
Q

Field names are case sensitive and field value are not.

A

True

163
Q

!= and NOT are same arguments.

A

False

164
Q

Query - status != 100:

A

Will return event where status field exist but value of that field is not 100.

165
Q

NOT status = 100:

A

Will return event where status field exist but value of that field is not 100 and all events where status field doesn’t exist.

166
Q

Will the queries following below get the same result?

1. index=log sourcetype=error_log status !=100 2. index=log sourcetype=error_log NOT status =100

A

No

167
Q

Select the best options for “search best practices” in Splunk

A

Select the time range always.
Try to specify index values.
Include as many search terms as possible.
Inclusion is generally better than exclusion.
Try to keep specific search terms.

168
Q

The better way of writing search query for index is:

A

(index=a OR index=b)

169
Q

Put query into separate lines where | (Pipes) are used by selecting following options.

A

Shift + Enter

170
Q

Fields are searchable key value pairs in your event data.

A

True

171
Q

Selected fields are a set of configurable fields displayed for each event.

A

True

172
Q

Following are the time selection option while making search

A
Date &amp; Time Range
Advanced 
Date Range 
Presets
Relative
173
Q

Search Language Syntax in Splunk can be broken down into the following components

A
Search term
Command 
Pipe 
Functions 
Arguments 
Clause