test 1 Flashcards
how many field extraction methods are there?
2
regular expression and delimiters
which command allows to perform search existing data models and their datasets from the search interface?
datamodel
by default what is the number of events per transaction?
1000
‘Event Type’ comes seventh in the search-time operations order
correct
it is a must to specify a statistical function when using the chart command
Correct
how many search types affect Splunk performance
4
Dense up to 50000 matching EPS
Sparse up to 5000 matching EPS
Super Sparse up to 2 seconds per index bucket
Rare from 10 to 20 index buckets per second
Splunk software knowledge can be grouped into how many categories?
5
Data interpretation– fields and field ectractions
Data Classification– Event Types and transactions
Data Enrichment– lookups and workflow actions
Data Normalisation– Tags and Aliases
Data Models
data model editor groups datasets into how many categories?
3
field extractions, lookups and eval expressions
a data model consist of how many categories?
3
Is it possible to apply field aliases to lookup?
No
True or False
Only root events can be accelerated
True
True or False
data model name and dataset name are case sensitive
True
Where is the occurrence of tags in the sequence of search time operations?
Last
true or false
the power user can create an object that persists across all apps
False
True or False
It is not possible to apply field aliases to lookups
False
True or False
as with chart, it is possible to split timechart by 2 fields
False
what does the gauge command allow you to do
set coloured ranges for a single-value visualisation
what allows you to categorise events based on search terms
Event Types
The time range specified for a historical search defines the……
amount of data fetched from the index matching that time range
what clause is used to group the output of a stats command by a specific name
Rex
when a search returns______, you can view the results as a list
statistical values
which function should you use with the transaction command to set the maximum total time between the earliest and latest events
maxspan
what attributes are required to create a POST workflow action?
XML attributes, URL, name
In what order are knowledge object/configurations applied?
Field Extraction, Lookups, Field Aliases
Can Auto-Extracted fields have their data type changed?
YES
True or False
A Macro is a reusable search string that may have a flexible time range
True
What happens when you click on a SEGMENT on a chart?
Adds the highlighted value to the search criteria
True or False
Useother=f
Split=t
Are valid options in the chart command
FALSE
What format does the CIM Add-on data models include?
JSON
When a search returns ________, you can view the results as a list
Statistical Values
True or False
Users can define the time range of the search when created the workflow action?
True