Filters
Question type

Study Flashcards

Universal forwarder is recommended for forwarding the logs to indexers.

A) True
B) False

Correct Answer

verifed

verified

Which is the default app for Splunk Enterprise?


A) Splunk Enterprise Security Suite
B) Searching and Reporting
C) Reporting and Searching
D) Splunk apps for Security

E) A) and B)
F) A) and C)

Correct Answer

verifed

verified

After running a search, what effect does clicking and dragging across the timeline have?


A) Executes a new search.
B) Filters current search results.
C) Moves to past or future events.
D) Expands the time range of the search.

E) A) and D)
F) A) and C)

Correct Answer

verifed

verified

Which search would return events from the access_combined sourcetype?


A) Sourcetype=access_combined
B) Sourcetype=Access_Combined
C) sourcetype=Access_Combined
D) SOURCETYPE=access_combined

E) All of the above
F) B) and D)

Correct Answer

verifed

verified

Which of the following file types is an option for exporting Splunk search results?


A) PDF
B) JSON
C) XLS
D) RTF

E) A) and D)
F) C) and D)

Correct Answer

verifed

verified

Which search will return the 15 least common field values for the dest_ip field?


A) sourcetype=firewall | rare num=15 dest_ip
B) sourcetype=firewall | rare last=15 dest_ip
C) sourcetype=firewall | rare count=15 dest_ip
D) sourcetype=firewall | rare limit=15 dest_ip

E) All of the above
F) None of the above

Correct Answer

verifed

verified

Which of the following describes lookup files?


A) Lookup fields cannot be used in searches.
B) Lookups contain static data available in the index.
C) Lookups add more fields to results returned by a search.
D) Lookups pull data at index time and add them to search results.

E) B) and D)
F) A) and B)

Correct Answer

verifed

verified

Showing 181 - 187 of 187

Related Exams

Show Answer