quiz 1 Flashcards

1
Q

Machine data is always structured.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Machine data is only generated by web servers.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Machine data makes up for more than ___% of the data accumulated by organizations.

A

90%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

index data

A

collect data from any source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

search & investigate

A

data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

add knowledge

A

label data for uniform

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which of these is not a main component of Splunk? earch and investigate
Collect and index data
Compress and archive
Add knowledge

A

Compress and archive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the three main processing components of Splunk?

A

Forwarders
Search Heads
Indexers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which function is not a part of a single instance deployment? Clustering
Searching
Indexing
Parsing

A

Clustering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

In most Splunk deployments, ________ serve as the primary way data is supplied for indexing.

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Search requests are processed by the ___________.

A

Indexers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

from the splunk bar you can

A

switch between apps, edit account, view messages, edit configs, monitor search jobs, help

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

app bar

A

navigate system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what are transforming commands

A

commands that create statistics and visualizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

search job is active for

A

10 minutes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

shared job good for

A

7 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

order of boolean

A

not, or, and

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

field values are case sensitive

A

false

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

wildcards can be used in field searches

A

yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

field names are

A

case sensitive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

what attributes describe “a dest 4”

A

a means contains string values and 4 values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

@ symbol does

A

round down. if 9:37, you will get results up until 9

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

different index examples

A

security data, web data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Having separate indexes allows:

A

Faster Searches.
Multiple retention policies
Ability to limit access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
As a general practice, exclusion is better than inclusion in a Splunk search.
False
26
What is the most efficient way to filter events in Splunk?
by time
27
Time to search can only be set by the time range picker.
False
28
Time to search can only be set by the time range picker.
False
29
What command would you use to remove the status field from the returned events?
fields -
30
Finish the rename command to change the name of the status field to HTTP Status.
status as "HTTP Status"
31
Which command removes results with duplicate field values?
Dedup
32
Which one of these is not a stats function? ``` Addtotals Count List Sum Avg ```
Addtotals
33
A time range picker can be included in a report.
true
34
In a dashboard, a time range picker will only work on panels that include a(n) __________ search.
inline
35
The User role can not create reports.
false
36
_____________ are reports gathered together into a single pane of glass.
Dashboards
37
The instant pivot button is displayed in the statistics and visualization tabs when a _______ search is run
non-transforming
38
Data models are made up of ___________.
datasets
39
Adding child data model objects is like the ______ Boolean in the Splunk search language.
AND
40
These are knowledge objects that provide the data structure for pivot.
Data models
41
Pivots can be saved as dashboards panels.
True
42
A lookup is categorized as a dataset.
True
43
External data used by a Lookup can come from sources like:
CSV files Scripts Geospatial data
44
When using a .csv file for Lookups, the first row in the file represents this.
Field names
45
To keep from overwriting existing fields with your Lookup you can use the ____________ clause.
outputnew
46
Finish this search command so that it displays data from the http_status.csv Lookup file.
inputlookup
47
Alerts can run uploaded scripts.
True
48
Alerts can be shared to all apps.
True
49
Real-time alerts will run the search continuously in the background.
true
50
Alerts can send an email.
True
51
Once an alert is created, you can no longer edit its defining search.
False
52
Machine data makes up for more than ___% of the data accumulated by organizations.
90%
53
Which function is not a part of a single instance deployment?
clustering
54
Splunk uses ________ to categorize the type of data being indexed
source type
55
Splunk knows where to break the event, where the time stamp is located and how to automatically create field value pairs using these.
Source types
56
Which following search mode toggles behavior based on the type of search being run?
Smart
57
When a search is sent to splunk, it becomes a _____.
search jobs
58
Shared search jobs remain active for _______ by default.
7 days
59
Field names are ________.
case sensitive
60
Field values are case sensitive.
false
61
Time to search can only be set by the time range picker.
False
62
What is the most efficient way to filter events in Splunk?
By time.
63
Would the ip column be removed in the results of this search? Why or why not?
No, because the name was changed.
64
What command would you use to remove the status field from the returned events?
fields -
65
Excluding fields using the Fields Command will benefit performance.
false
66
Which clause would you use to rename the count field?
as
67
How many results are shown by default when using a Top or Rare Command?
10
68
_____________ are reports gathered together into a single pane of glass.
dashboards
69
inish this search command so that it displays data from the http_status.csv Lookup file.
inputlookup