Splunk Flashcards
Fundamentals 1 and 2
Machine data is always structured.
False
Machine data makes up for more than _____% of the data accumulated by organizations.
90
Machine data can give you insights into:
Application performance Security Hardware monitoring Sales User Behavior
Machine data is only log files on web servers.
False
Which of these is NOT a main component of Splunk?
compress and archive
The index does not play a major role in Splunk.
False
Data is broken into single events by:
in a consistent format.
Which role defines what apps a user will see by default?
Admin
Which two apps ship with Splunk Enterprise?
Search & Reporting
Home App
There are ______ components to the Search and Reporting app’s default interface.
7
What is the most efficient way to filter events in Splunk?
reverse chronological order
Commands that create statistics or visualizations are called ____________.
transforming commands
The Search & Reporting App has how many search modes?
3
Which character acts as a wildcard in the Splunk Search Language?
*
What are Boolean operators in Splunk?
…
Which is not a comparison operator in Splunk?
&=
Field names are _____________.
case sensitive
What could be said of the circled field below:
A dest 4
it contains four values
its was extracted at search time
it contains string values
After a report is saved, you can no longer edit the search.
False
Search commands can be used with search terms to do the following:
Create charts
Compute statistics
Format data
If we want to see events after running a transforming command, we need to switch to this mode.
Verbose
Any search that returns these values can be viewed as a chart.
Statistical
Charts can be based on numbers, time or location.
True
________ are searches gathered together in a single pane of glass.
Dashboards