Splunk Flashcards

(76 cards)

1
Q

Machine data makes up for more than ___% of the data accumulated by organizations.

A

90%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Machine data is always structured.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Machine data is only generated by web servers.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the three main processing components of Splunk?

A

Forwarders, Search Heads, & Indexers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Search strings are sent from the _________.

A

Search Heads

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In most Splunk deployments, ________ serve as the primary way data is supplied for indexing.

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which function is not a part of a single instance deployment?

A

Clustering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A single-instance deployment of Splunk Enterprise handles:

A

Indexing Search, Parsing, & Input

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the three main default roles in Splunk Enterprise?

A

Admin, User, & Power

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which apps ship with Splunk Enterprise?

A

Home App & Search & Reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

This role will only see their own knowledge objects and those that have been shared with them.

A

User

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

_________ define what users can do in Splunk.

A

Roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The password for a newly installed Splunk instance is:

A

Created when you install Splunk Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Files indexed using the upload input option get indexed _____.

A

Once

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Splunk uses ________ to categorize the type of data being indexed.

A

Sourcetype

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The monitor input option will allow you to continuously monitor files.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Splunk knows where to break the event, where the time stamp is located and how to automatically create field value pairs using these.

A

Source Type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

In most production environments, _______ will be used as the source of data input.

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Events are always returned in chronological order.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Which following search mode toggles behavior based on the type of search being run?

A

Smart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the order of evaluation for Boolean operations in Splunk?

A

NOT, OR, & AND

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

When zooming in on the event timeline, a new search is run.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Shared search jobs remain active for _______ by default.

A

7 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Field names are ________.

A

Case sensitive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
What attributes describe the circled field below?
It contains 4 values and a string value
26
Field values are case sensitive
False
27
Which is not a comparison operator in Splunk?
?=
28
Wildcards cannot be used with field searches.
False
29
What is the most efficient way to filter events in Splunk?
By time
30
Time to search can only be set by the time range picker.
False
31
As a general practice, exclusion is better than inclusion in a Splunk search.
False
32
Having separate indexes allows:
Faster searches, ability to limit access and multiple retention policies.
33
This symbol is used in the "Advanced" section of the time range picker to round down to nearest unit of specified time.
@
34
What command would you use to remove the status field from the returned events? Search string: sourcetype=a* status=404 | _______ status (Last 24 hours)
Field
35
Excluding fields using the Fields Command will benefit performance.
False
36
What is missing from this search? Search: sourcetype=a* | rename IP as "User IP" | table User IP
A question mark around User IP.
37
Finish the rename command to change the name of the status field to HTTP Status.
Search: sourcetype=a* status=404 | rename _________ status as "HTPP Status"
38
Would the IP column be removed in the results of this search? Why or why not?
No, because the name was changed
39
Which one of these is not a stats function?
Addtotals
40
How many results are shown by default when using a Top or Rare Command?
10
41
Which stats function would you use to find the average value of a field?
Avg
42
Which clause would you use to rename the count field? Search: sourcetype=vendor* | stats count __ "Units Sold"
As
43
To display the most common values in a specific field, what command would you use?
Top
44
A time range picker can be included in a report.
True
45
The User role cannot create reports.
False
46
Charts can be based on numbers, time, or location.
True
47
These roles can create reports:
User, Power, & Admin
48
_____________ are reports gathered together into a single pane of glass.
Dashboards
49
Pivots cannot be saved as reports panels.
False
50
Which role(s) can create data models?
Admin & Power
51
These are knowledge objects that provide the data structure for pivot.
Data models
52
Pivots can be saved as dashboards panels.
True
53
Data models are made up of ___________.
Datasets
54
A lookup is categorized as a dataset.
True
55
Finish this search command so that it displays data from the http_status.csv Lookup file.
Inputlookup Search: ___ http __status.csv
56
To keep from overwriting existing fields with your Lookup you can use the ____________ clause.
Outputnew
57
When using a .csv file for Lookups, the first row in the file represents this.
Field names
58
External data used by a Lookup can come from sources like:
Geospatial data, scripts, & csv files
59
Alerts can run uploaded scripts.
True
60
Once an alert is created, you can no longer edit its defining search.
False
61
Alerts can send an email.
True
62
Alerts can be shared to all apps.
True
63
Real-time alerts will run the search continuously in the background
True
64
Which of these is not a main component of Splunk?
Compress & archive
65
Which function is not a part of a single instance deployment?
Clustering
66
Which apps ship with Splunk Enterprise?
Search & reporting & home app
67
You can launch and manage apps from the home app.
True
68
This role will only see their own knowledge objects and those that have been shared with them.
User
69
Splunk uses ________ to categorize the type of data being indexed.
Source types
70
Splunk knows where to break the event, where the time stamp is located and how to automatically create field value pairs using these.
Source types
71
Files indexed using the upload input option get indexed _____.
Once
72
The time stamp you see in the events is based on the time zone in your user account.
True
73
How is the asterisk used in Splunk search?
A wildcard
74
Have values in at least 20% of the events.
Interesting fields
75
Which command removes results with duplicate field values?
Dedup
76
How would you show the top five vendors without showing the percentage field?
... | top Vendor limit=5 showperc=f