Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Splunk Core Certified User SPLK-1001 Exam Questions

Page: 1 / 17 Total 244 questions

Want more questions? Get Premium Access.

Question 1

Which statement is true about Splunk alerts?

Correct Answer: A. Alerts are based on searches that are either run on a scheduled interval or in real-time.

Question 2

Which command is used to validate a lookup file?

Correct Answer: C. I inputlookup products.csv

Question 3

Following are the time selection option while making search:

(Choose all that apply.)

Correct Answer: B. Advanced

Question 4

The stats command will create a _____________ by default.

Correct Answer: A. Table

Question 5

What is a primary function of a scheduled report?

Correct Answer: D. Triggering an alert in your Splunk instance when certain conditions are met

Question 6

You are able to create new Index in Data Input settings.

Correct Answer: B. Yes

Question 7

When is an alert triggered?

Correct Answer: D. When results of a search meet a specifically defined condition
Explanation:

Explanation/Reference:


+triggered+When+results+of+a+search+meet+a+specifically+defined

+condition&source=bl&ots=avtEx5luxo&sig=ACfU3U1ZVob_j9nU243Te2vhqwxI3YvJuA&hl=en&sa=X&ved=2a

hUKEwjm48rmkfXoAhUlMewKHb_FAbkQ6AEwB3oECBYQJg

Question 8

When a Splunk search generates calculated data that appears in the Statistics tab. in what formats can the results be exported?

Correct Answer: D. Raw Events, CSV, XML, JSON

Question 9

Field values are case sensitive.

Correct Answer: B. False

Question 10

According to Splunk best practices, which placement of the wildcard results in the most efficient search?

Correct Answer: C. fail*

Question 11

Where does Licensing meter happen?

Correct Answer: A. Indexer

Question 12

Which of the following is the appropriately formatted SPL search?

Correct Answer: A. index=security sourcetype=linux secure (invalid OR failed) | stats count as 'Potential Issues'
Explanation:

This is the appropriately formatted SPL search because it follows the SPL syntax rules12, such as:

Using the=operator to specify field-value pairs, such asindex=securityandsourcetype=linux.

Using theORoperator to combine multiple values for the same field, such as(invalid OR failed).

Using the|character to separate commands, such asstats count as 'Potential Issues'.

Using theaskeyword to rename fields, such ascount as 'Potential Issues'.


Question 13

Matching search terms are highlighted.

Correct Answer: A. Yes

Question 14

Uploading local files though Upload options index the file only once.

Correct Answer: B. Yes

Question 15

What is the result of the following search?

index=myindex source=c: \mydata. txt NOT error=*

Correct Answer: C. Only data that does not contain the error field will be displayed.
Explanation:

The search query index=myindex source=c: \mydata. txt NOT error=* specifies three criteria for the events to be returned:

The index must be myindex, which is a user-defined index that contains the data from a specific source or sources.

The source must be c: \mydata. txt, which is the name of the file or directory where the data came from.

The error field must not exist in the events, which is indicated by the NOT operator and the wildcard character (*).

The NOT operator negates the following expression, which means that it returns the events that do not match the expression. The wildcard character () matches any value, including an empty value or a null value. Therefore, the expression NOT error=means that the events must not have an error field at all, regardless of its value.

The search query does not use quotation marks around the source value, which means that it is case-sensitive and exact. If there are any variations in the source name, such as capitalization or spacing, they will not match the query.

Reference

Search command syntax details

Search command examples

Basic searches and search results