User FlashCards
The Common constraints for the top command are?
limit
countfield
showperc
What is the limit= to when you click the Top values in a field window?
The limit is =20
Limit=0 returns how many results
Unlimited results
By default what is the name of the countfield?
Count
Shows the number of events that match the search criteria
stats count
Returns a count of unique values for a given field?
distinct_count, dc
Shows all values of a given field?
list
Shows unique values of a given field?
values
What are saved searches?
Reports
Does running a report return fresh results each time you run it?
Yes!
____ and ____ allow you to drill down by default to see the underlying events.
Statistics and Visualizations
Can reports be shard and added to dashboards?
Yes!
The report is saved with the time range that was selected when it was created. True or False?
True!
Adding a time range picker allows you to do what to the Report?
It allows you to adjust the time range of the Report when you run it.
What are the dialog buttons when creating a report?
- Continue Editing
- Add to Dashboard
- View - allows you to display and rerun the report
There are 3 main ways to create tables and visualizations in Splunk. What are they?
- Select a field from the fields sidebar and choose a report to run
- User the Pivot interface
- Start with a dataset or Instant Pivot - Use the Splunk search language transforming commands in the Search bar.
Numeric fields have 6 report types with mathematical functions, what are they?
- Average over time
- Maximum value over time
- Minimum value over time
- Top values
- Top values by time
- Rare values
For alphanumeric character fields, there are only 3 available reports, what are they?
- Top values
- Top values by time
- Rare values
When updating visualization settings like the min/max, how soon are the new settings reflected?
Immediately!!
Switch to what tab in order to view the data as a table?
Statistics!
What is a dashboard?
A dashboard consists of one or more panels displaying data visually in a useful way - such as events, tables, or charts.
Page 150 Mod 10
Why create panels from reports?
It is efficient to create most dashboard panels based on reports because
- a single report can be used across different dashboards
- this links the report definition to the dashboard
Any change to the underlying report affects every dashboard panel that utilizes that report.
Page 154 Mod 10
Dashboards can be exported as…
as a PDF or Printed
The selection screen screen under Export shows:
PDF
Schedule PDF Delivery
Print
Page 160 Mod 10
How do you create an Instant Pivot?
- Execute a search (search criteria only, no search commands)
- Click the Statistics or Visualization tab
- Click the Pivot icon
- Select the fields to be included in the data model object
- Create the pivot (table or chart)