Splunk Power User 1002 Flashcards
Search Terms are not Case Sensitive? T or F
True
Command names are not Case Sensitive? T or F
True
Clauses and Functions are not case sensitive? T or F
True
If a command references a specific value, that value (Is / Is Not) case sensitive?
IS
What values from lookup tables ARE case-sensitive by default?
Field. Users with Admin Roles can set field values to not be case sensitive.
Booleans ARE Case Sensitive. T or F
True
Tag Values ARE case sensitive. T or F
True
Buckets have directories containing sets of:
Raw Data and indexing data
Buckets have configurable what set by admin users?
max size & max time span
What are the 3 searchable buckets in Splunk?
Hot, Warm, and Cold
When are “Hot” buckets rolled into “warm” buckets?
when it reaches max size, max time span, or indexer is restarted
When Splunk search is run, Splunk uses what on bucket directories to determine if it needs to open the bucket, uncompress raw data, and search content inside?
Timestamps
Wildcards are tested after all other search terms. T or F
True
Only ____ wildcards make efficient use of index
trailing
What happens when there is a wildcard at the beginning of a string?
Splunk searches all events in that time frame.
Wildcards ______ of string can cause inconsistent results
in the middle
Should you use wildcards to match punctuation?
No
What are the 3 search modes in Splunk?
Fast, Smart, and Verbose
As events are stored by time, what is the most efficient filter?
Time
After time, the default fields for _______ are most powerful.
index, source, host, and sourcetype.
o These fields are extracted at index time and do not need to be extracted for each search
o Use these fields to filter as early as possible in a search so processing is done on a minimum amount of data
Use _____ command to extract only the fields you will need for your search
“fields”
When should you apply filtering commands?
As early as possible
Helps determine which phase of a search is taking up the most time
Search Job Inspector
Search Job Inspector dissects the behavior of searches to help understand execution costs of ____ within a search.
knowledge objects, search commands, & other components