Questions Flashcards
What determines the scope of data that appears in a scheduled report?
Permissions granted by the owner of report.
When writing searches in Splunk.what is true about Booleans?
They must be uppercase.
How can search results be kept for longer than 7 days?
Changing job settings
When running searches, command modifiers are displayed in what colour?
Orange
Which of the following is a Splunk search best practice?
Filter as early as possible
How are events displayed after a search is executed?
Reverse chronological order
What is the primary function of a scheduled report?
Triggering an alert in your Splunk instance when certain conditions are met
Which commands is used to review the contents of a specified static lookup file?
inputlookup
When sorting on multiple fields with the sort command, what delimiter can be used between the field names in the search?
,
Which of the following about case sensitivity is true?
Field names ARE case sensitive; field values are NOT
What does the rare command do?
Returns the least common field values of a given field in the results.
Which Boolean operator is always implied between two search terms, unless otherwise specified?
AND
What is the purpose of using a by clause with the stats command?
To group the results by one or more fields
How can you add a field to the fields sidebar?
Click All Fields and select the field to add it to Selected Fields
In the fields sidebar, which character denotes alpha numeric field values?
a
How does Splunk determine which fields to extract from data?
Splunk automatically discovers many fields based on sourcetype and key/value pairs found in data.