Splunk 7.x Fundmentals Part1 & Others Flashcards
Machine data is always structured.
Select your answer.
True
False
False
Machine data makes up for more than ___% of the data accumulated by organizations.
Select your answer. 10 90 25 50
90%
Machine data is only generated by web servers.
Select your answer.
False
True
False
Search requests are processed by the ___________.
Select your answer.
Forwarders
Indexers
Search Heads
Indexers
A single-instance deployment of Splunk Enterprise handles:
Select all that apply. Indexing Input Searching Parsing
Indexing
Searching
Parsing
Which of these is not a main component of Splunk?
Select your answer. Collect and index data Compress and archive Search and investigate Add knowledge
Compress and archive
In most Splunk deployments, ________ serve as the primary way data is supplied for indexing.
Select your answer.
Search Heads
Forwarders
Local Files
Forwarders
Which function is not a part of a single instance deployment?
Select your answer. Searching Indexing Clustering Parsing
Clustering
Which apps ship with Splunk Enterprise?
Select all that apply. Sideview Utils DB Connect Search & Reporting Home App
Search & Reporting
Home App
What are the three main default roles in Splunk Enterprise?
Select all that apply. Admin User King Manager Power
Admin
User
Power
_________ define what users can do in Splunk.
Select your answer.
Tokens
Disk permissions
Roles
Roles
You can launch and manage apps from the home app.
Select your answer.
False
True
True
The password for a newly installed Splunk instance is:
Select your answer. Your email address. Randomly generated. Created when you install Splunk Enterprise. Available from the splunk.com website.
Created when you install Splunk Enterprise.
This role will only see their own knowledge objects and those that have been shared with them.
Select your answer.
User
Admin
Power
User
In most production environments, _______ will be used as the source of data input.
Fill in the blank.
Forwarders
The monitor input option will allow you to continuously monitor files.
Select your answer.
True
False
True
Splunk knows where to break the event, where the time stamp is located and how to automatically create field value pairs using these.
Select your answer.
Source types
Line breaks
File names
Source types
Splunk uses ________ to categorize the type of data being indexed.
Fill in the blank.
source types
Files indexed using the the upload input option get indexed _____.
Select your answer. Every hour On every search Once Each time Splunk restarts
Once
The time stamp you see in the events is based on the time zone in your user account.
Select your answer.
True
False
True
How is the asterisk used in Splunk search?
Select your answer. To make a nose for your clown emoticon As a wildcard As a place holder To add up numbers
As a wildcard
Events are always returned in chronological order.
Select your answer.
True
False
False
A search job will remain active for ___ minutes after it is run.
Select your answer. 10 30 5 90 20
10
Commands that create statistics and visualizations are called _______________ commands.
Fill in the blank.
transforming
When zooming in on the event time line, a new search is run.
Select your answer.
False
True
False
When a search is sent to splunk, it becomes a _____.
Select your answer. Search job Task for Jimmy the Splunk elf Event File on the host system
Search job
What is the order of evaluation for Boolean operations in Splunk?
Drag and drop into the correct order.
AND NOT OR
NOT
OR
AND
These are booleans in the Splunk Search Language.
Select all that apply. OR IF AND NOT
OR
AND
NOT
Which following search mode toggles behavior based on the type of search being run?
Select your answer.
Fast
Verbose
Smart
Smart
These searches will return the same results.
failed password
failed AND password
Select your answer.
False
True
True
Wildcards cannot be used with field searches.
Select your answer.
True
False
False
What attributes describe the circled field below?
a dest 4
Select all that apply. It contains numerical values It contains 4 values. It cannot be used in a search. It contains string values.
It contains 4 values.
It contains string values.
Field names are ________.
Select all that apply. Always capitalized Case insensitive Case sensitive Not important in Splunk
Case sensitive
Which is not a comparison operator in Splunk?
Select your answer. ?= = <= != >
?=
Field values are case sensitive.
Select your answer.
False
True
False
As a general practice, exclusion is better than inclusion in a Splunk search.
Select your answer.
True
False
False