quiz 1 Flashcards

1
Q

Machine data is always structured.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Machine data is only generated by web servers.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Machine data makes up for more than ___% of the data accumulated by organizations.

A

90%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

index data

A

collect data from any source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

search & investigate

A

data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

add knowledge

A

label data for uniform

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which of these is not a main component of Splunk? earch and investigate
Collect and index data
Compress and archive
Add knowledge

A

Compress and archive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the three main processing components of Splunk?

A

Forwarders
Search Heads
Indexers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which function is not a part of a single instance deployment? Clustering
Searching
Indexing
Parsing

A

Clustering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

In most Splunk deployments, ________ serve as the primary way data is supplied for indexing.

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Search requests are processed by the ___________.

A

Indexers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

from the splunk bar you can

A

switch between apps, edit account, view messages, edit configs, monitor search jobs, help

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

app bar

A

navigate system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what are transforming commands

A

commands that create statistics and visualizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

search job is active for

A

10 minutes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

shared job good for

A

7 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

order of boolean

A

not, or, and

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

field values are case sensitive

A

false

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

wildcards can be used in field searches

A

yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

field names are

A

case sensitive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

what attributes describe “a dest 4”

A

a means contains string values and 4 values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

@ symbol does

A

round down. if 9:37, you will get results up until 9

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

different index examples

A

security data, web data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Having separate indexes allows:

A

Faster Searches.
Multiple retention policies
Ability to limit access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

As a general practice, exclusion is better than inclusion in a Splunk search.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What is the most efficient way to filter events in Splunk?

A

by time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Time to search can only be set by the time range picker.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Time to search can only be set by the time range picker.

A

False

29
Q

What command would you use to remove the status field from the returned events?

A

fields -

30
Q

Finish the rename command to change the name of the status field to HTTP Status.

A

status as “HTTP Status”

31
Q

Which command removes results with duplicate field values?

A

Dedup

32
Q

Which one of these is not a stats function?

Addtotals
Count
List
Sum
Avg
A

Addtotals

33
Q

A time range picker can be included in a report.

A

true

34
Q

In a dashboard, a time range picker will only work on panels that include a(n) __________ search.

A

inline

35
Q

The User role can not create reports.

A

false

36
Q

_____________ are reports gathered together into a single pane of glass.

A

Dashboards

37
Q

The instant pivot button is displayed in the statistics and visualization tabs when a _______ search is run

A

non-transforming

38
Q

Data models are made up of ___________.

A

datasets

39
Q

Adding child data model objects is like the ______ Boolean in the Splunk search language.

A

AND

40
Q

These are knowledge objects that provide the data structure for pivot.

A

Data models

41
Q

Pivots can be saved as dashboards panels.

A

True

42
Q

A lookup is categorized as a dataset.

A

True

43
Q

External data used by a Lookup can come from sources like:

A

CSV files
Scripts
Geospatial data

44
Q

When using a .csv file for Lookups, the first row in the file represents this.

A

Field names

45
Q

To keep from overwriting existing fields with your Lookup you can use the ____________ clause.

A

outputnew

46
Q

Finish this search command so that it displays data from the http_status.csv Lookup file.

A

inputlookup

47
Q

Alerts can run uploaded scripts.

A

True

48
Q

Alerts can be shared to all apps.

A

True

49
Q

Real-time alerts will run the search continuously in the background.

A

true

50
Q

Alerts can send an email.

A

True

51
Q

Once an alert is created, you can no longer edit its defining search.

A

False

52
Q

Machine data makes up for more than ___% of the data accumulated by organizations.

A

90%

53
Q

Which function is not a part of a single instance deployment?

A

clustering

54
Q

Splunk uses ________ to categorize the type of data being indexed

A

source type

55
Q

Splunk knows where to break the event, where the time stamp is located and how to automatically create field value pairs using these.

A

Source types

56
Q

Which following search mode toggles behavior based on the type of search being run?

A

Smart

57
Q

When a search is sent to splunk, it becomes a _____.

A

search jobs

58
Q

Shared search jobs remain active for _______ by default.

A

7 days

59
Q

Field names are ________.

A

case sensitive

60
Q

Field values are case sensitive.

A

false

61
Q

Time to search can only be set by the time range picker.

A

False

62
Q

What is the most efficient way to filter events in Splunk?

A

By time.

63
Q

Would the ip column be removed in the results of this search? Why or why not?

A

No, because the name was changed.

64
Q

What command would you use to remove the status field from the returned events?

A

fields -

65
Q

Excluding fields using the Fields Command will benefit performance.

A

false

66
Q

Which clause would you use to rename the count field?

A

as

67
Q

How many results are shown by default when using a Top or Rare Command?

A

10

68
Q

_____________ are reports gathered together into a single pane of glass.

A

dashboards

69
Q

inish this search command so that it displays data from the http_status.csv Lookup file.

A

inputlookup